CVE-2026-63456 PUBLISHED

Authentication bypass via spoofed HTTP headers Orchestrator REST API

Assigner: hpe
Reserved: 16.07.2026 Published: 04.08.2026 Updated: 04.08.2026

Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify potentially sensitive information on the target system.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor Hewlett Packard Enterprise (HPE)
Product EdgeConnect SD-WAN Orchestrator
Versions Default: unaffected
  • affected from 9.6.2.00000 to 9.6.2.40208 (incl.)
  • affected from 9.6.3.00000 to 9.6.3.40137 (incl.)

Credits

  • This vulnerability was discovered and reported by Christopher Alejandro (Moroco) through HPE Aruba Networking's Bug Bounty program reporter

References