CVE-2026-76672
CVE-2026-76672: 1 tracked advisory record across Aruba. Compare vendor sources.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Aruba
1 advisory- Advisory severityCritical9.9
Critical [CVE-2026-76672] Authenticated Sensitive Information Disclosure in HPE Networking EdgeConnect SD-WAN Orchestrator
CVE-2026-76672Source published Source updated
A vulnerability exists in the SD-WAN Orchestrator that may lead to the exposure of sensitive configuration information. An authenticated remote attacker with read-only privileges could exploit this vulnerability by sending a specially crafted request to the cache synchronization endpoint. Successful exploitation could result in the disclosure of sensitive third-party API tokens and credentials, potentially enabling lateral movement to external security platforms. Affected product named by the advisory: EdgeConnect SD-WAN Gateways.
- Affected products in this advisory
- EdgeConnect SD-WAN Gateways
- Source-reported affected versions
- EdgeConnect SD-WAN Gateways through 9.7.0
- EdgeConnect SD-WAN Gateways 9.6.0 through 9.6.3
- EdgeConnect SD-WAN Gateways 9.5.0 through 9.5.8
- EdgeConnect SD-WAN Gateways 9.4.0 through 9.4.10
- Source-reported fixed versions
- No fixed-version detail extracted. This does not mean no fix exists.
- Mitigation guidance
- No mitigation guidance extracted; consult the source.
Android app · Google Play
Monitor future Aruba CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.