Skip to content

Hewlett Packard Enterprise EdgeConnect: server-side request forgery

High8.5CVE-2026-76680 · Published Sep 15, 2026 · updated Sep 25, 2026

Vulnerabilities in the API of EdgeConnect SD-WAN Orchestrator could allow a remote attacker authenticated with low privileges to conduct server-side request forgery (SSRF) attacks. A successful exploit allows an attacker to enumerate information about the internal structure of the EdgeConnect SD-WAN Orchestrator host leading to potential disclosure of sensitive information beyond what is authorized by the user's existing privilege level.

Affected versions

PackageAffectedFixed in
EdgeConnect SD-WAN Gateways
Product
>= 9.7.0, <= 9.7.0No fix yet
>= 9.6.0, <= 9.6.3No fix yet
>= 9.5.0, <= 9.5.8No fix yet
>= 9.4.0, <= 9.4.10No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-918

More Hewlett Packard Enterprise advisories

All Hewlett Packard Enterprise

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.