nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-63456 CVE-2026-63456
CRITICAL
Authentication bypass via spoofed HTTP headers Orchestrator REST API
Record summary
CVE-2026-63456 has a selected CVSS score of 9.8 (critical).
Description
Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify potentially sensitive information on the target system.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 4, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
EdgeConnect SD-WAN OrchestratorBrowse Hewlett Packard Enterprise (HPE) / EdgeConnect SD-WAN OrchestratorDefault status: unaffected | CVE List | 9.6.2.00000 to ≤ 9.6.2.40208 | affected |
| 9.6.3.00000 to ≤ 9.6.3.40137 | affected |
References
2support.hpe.com
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05100en_us&docLocale=en_US