Hewlett Packard EnterpriseCVE-2026-44878
Hewlett Packard Enterprise EdgeConnect SD-WAN Gateway: insecure permissions
High7.2CVE-2026-44878 · Published Jul 21, 2026 · updated Jul 23, 2026
A vulnerability in the web-based management interface of an ECOS device could allow a highly privileged, authenticated remote attacker to access the device's filesystem. Successful exploitation of this vulnerability could allow an attacker to access sensitive files and tamper with or delete system data.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| EdgeConnect SD-WAN Gateway (ECOS) Product | >= 9.4.0.0, <= 9.4.6.0 | No fix yet |
| >= 9.5.0.0, <= 9.5.6.0 | No fix yet | |
| >= 9.6.0.0, <= 9.6.1.0 | No fix yet |
Details and references
More Hewlett Packard Enterprise advisories
All Hewlett Packard Enterprise| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 4 | Hewlett Packard Enterprise EdgeConnect: information disclosure | Critical9.8 | No fix yet |
| Jul 21 | Hewlett Packard Enterprise EdgeConnect SD-WAN Gateway (ECOS): command injection | High7.2 | No fix yet |
| Jul 21 | Hewlett Packard Enterprise AOS-CX: buffer overflow | High7.2 | 10.18.0001 |
| Jul 21 | Hewlett Packard Enterprise AOS-CX: path traversal | High7.2 | 10.18.0001 |
| Jul 21 | Hewlett Packard Enterprise AOS-CX: buffer overflow | High8.8 | 10.18.0001 |
| Jul 7 | Hewlett Packard Enterprise HPE Networking Instant On: information disclosure | Medium6.5 | No fix yet |