REST API Interface Vulnerabilities in HPE Networking SD-WAN Orchestrator
CVE-2026-63456
9.8CRITICAL
What is CVE-2026-63456?
Multiple vulnerabilities have been identified in the REST API interface of HPE Networking SD-WAN Orchestrator. These vulnerabilities could potentially be exploited by unauthenticated remote attackers, enabling them to circumvent authentication mechanisms. This breach may grant access to critical system functions, allowing attackers to view and modify sensitive information contained within the system. It is crucial for users and administrators to be aware of these vulnerabilities and take appropriate measures to mitigate any potential risks.
Affected Version(s)
EdgeConnect SD-WAN Orchestrator 9.6.2.00000 <= 9.6.2.40208
EdgeConnect SD-WAN Orchestrator 9.6.3.00000 <= 9.6.3.40137
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This vulnerability was discovered and reported by Christopher Alejandro (Moroco) through HPE Aruba Networking's Bug Bounty program
