nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-63455 CVE-2026-63455
CRITICAL
Authentication bypass via spoofed HTTP headers Orchestrator REST API
Record summary
CVE-2026-63455 has a selected CVSS score of 9.8 (critical).
Description
Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify potentially sensitive information on the target system.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 4, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
EdgeConnect SD-WAN OrchestratorBrowse Hewlett Packard Enterprise (HPE) / EdgeConnect SD-WAN OrchestratorDefault status: unaffected | CVE List | 9.6.2.00000 to ≤ 9.6.2.40208 | affected |
| 9.6.3.00000 to ≤ 9.6.3.40137 | affected |
References
2support.hpe.com
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05100en_us&docLocale=en_US