CVE-2026-76675 PUBLISHED

Authenticated Command Injection Vulnerability Leads to Privilege Escalation in EdgeConnect SD-WAN Gateways

Assigner: hpe
Reserved: 19.08.2026 Published: 15.09.2026 Updated: 15.09.2026

A command injection vulnerability exists in the command line interface of EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker with high privileges to execute arbitrary commands on the underlying operating system leading to complete system compromise.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 9.1

Product Status

Vendor Hewlett Packard Enterprise (HPE)
Product EdgeConnect SD-WAN Gateways
Versions Default: affected
  • affected from 9.7.0.0 to 9.7.0.0 (incl.)
  • affected from 9.6.0.0 to 9.6.3.1 (incl.)
  • affected from 9.5.0.0 to 9.5.8.1 (incl.)
  • affected from 9.4.0.0 to 9.4.8.2 (incl.)

Credits

  • Internal security research (HPE Networking). reporter

References