Description
A vulnerability exists in an Orchestrator service that could allow an unauthenticated remote attacker to bypass multi-factor authentication requirements. Successful exploitation could allow an attacker to create an admin user account without the necessary multi-factor authentication, thereby compromising the integrity of secured access to the system.
Related CPE's
a
arubanetworks
edgeconnect_sd-wan_orchestrator
5
References
Weaknesses
134c704f-9b21-4f2e-91b3-4a467353bcc0
Secondary
CWE-287
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
6.5 · Medium
Information
Source identifier
Vulnerability status
Analyzed
Published
2026-01-14T17:16:06.300Z
6 days agoLast modified
2026-01-20T18:15:55.017Z
9 hours ago