#VU121594 Improper authentication in EdgeConnect Enterprise Orchestrator - CVE-2025-37184
Published: January 15, 2026
EdgeConnect Enterprise Orchestrator
Aruba Networks
Description
The vulnerability allows a remote user to bypass multi-factor authentication.
The vulnerability exists due to an error in the authentication process, which allows to create an administrative account without disabled multi-factor authentication. A remote attacker with ability to obtain or brute-force a password can gain unauthorized access to the system.