External risk intelligence

Aruba EdgeConnect SD-WAN Orchestrator Sensitive Information Disclosure Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2026-76672

The vulnerability affects an SD-WAN Orchestrator, which is a management appliance typically deployed at the edge of a network to manage distributed infrastructure. These systems are commonly network-accessible for administrative and orchestration purposes, making them a likely target for external exposure in enterprise deployments.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability has been identified in the SD-WAN Orchestrator, a system used to manage network infrastructure. This issue could allow an attacker with limited access to potentially expose sensitive API tokens and credentials. This could, in turn, enable unauthorized access to external security systems.

  • Sensitive credentials could be exposed.
  • Orchestrator systems manage critical network functions.
  • Confirm relevance and exposure of your SD-WAN Orchestrator.

Attack Path

How an attacker could exploit the issue

An attacker with read-only access to the SD-WAN Orchestrator can send a specially crafted request to a specific endpoint. This action targets the cache synchronization feature within the orchestrator. If successful, the attacker could gain access to sensitive information like third-party API tokens and credentials. This exposure could then be leveraged for further unauthorized access to external security platforms, facilitating lateral movement within the network.

  • Read-only access required to start.
  • Cache synchronization endpoint is the trigger.
  • Sensitive information exposure and lateral movement risk.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could expose sensitive configuration details from the SD-WAN Orchestrator. An attacker with read-only access could send a crafted request to a cache synchronization endpoint, potentially revealing third-party API tokens and credentials.

  • Sensitive configuration information and API tokens.
  • Attacker sends crafted request to synchronization endpoint.
  • Enables lateral movement to external platforms.

Operational Fix

Recommended remediation, mitigation, and detection steps

Application owners and platform teams responsible for the SD-WAN Orchestrator must prioritize identifying all deployed instances and confirming their exposure and criticality. The first step involves locating the affected technology, verifying its reachability and business impact, and assigning ownership before planning a risk-based remediation strategy.

  • Platform and security teams own the issue.
  • Verify external reachability and business criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Aruba EdgeConnect SD-WAN Orchestrator?

This software acts as a centralized management platform for wide-area network infrastructure. Organizations use it to configure, monitor, and automate connectivity across distributed sites, effectively serving as the control center for their SD-WAN deployment. Because it orchestrates critical network functions, it manages highly sensitive configuration data and credentials required to talk to other internal and external security services.

How would you explain the weakness in CVE-2026-76672?

This is a CWE-200 vulnerability, which refers to the unauthorized exposure of sensitive information. In this specific case, the software fails to properly protect configuration data during cache synchronization. By exploiting this flaw, an attacker can trick the system into revealing valuable secrets, such as API tokens and credentials, that the orchestrator uses to interact with third-party security platforms.

What is required to trigger this vulnerability?

An attacker must already have read-only access to the SD-WAN Orchestrator to attempt this. They trigger the flaw by sending a specially crafted request to the cache synchronization endpoint. It is important to note that this process does not involve standard administrative actions or general system usage; it requires targeting this specific internal mechanism to cause the data leak.

Is my instance at risk according to Halo Surface Signal?

Halo Surface Signal indicates a 'Likely' risk level for this CVE. Because SD-WAN Orchestrator appliances are designed to manage distributed infrastructure, they are often placed in network-accessible locations for administrative reach. If your orchestrator is accessible from the internet or exposed to untrusted network segments, it is more likely to be reachable by an attacker attempting this request.

What should I do if I run this software?

Prioritize identifying all deployed instances of the SD-WAN Orchestrator within your environment. Verify whether these instances are reachable from the network, particularly if they are internet-facing. Assign clear ownership to the platform or security teams responsible for these systems so they can assess the business criticality and coordinate the necessary security updates or configuration changes.

References