Junglewise Threat Intelligence

CVE-2026-63455: HPE Networking SD-WAN Orchestrator REST API authentication bypass

CVE-2026-63455 · Severity: critical · CVSS 9.8 · Published 2026-08-04

Vendors: Hpe.

Executive brief

HPE Networking SD-WAN Orchestrator is a centralized management platform for software-defined wide-area networks used by enterprises to optimize network traffic. A vulnerability in its REST API allows unauthenticated attackers to bypass authentication and gain unauthorized access to the system, enabling them to read and modify sensitive network configuration and operational data without credentials.

Technical details

Multiple vulnerabilities exist in the REST API interface of HPE Networking SD-WAN Orchestrator that permit unauthenticated remote attackers to circumvent web authentication mechanisms. The vulnerabilities enable attackers on the network to directly invoke protected system functions and access sensitive information through API endpoints. The attack requires network reachability to the REST API interface but no prior authentication or user interaction. Successful exploitation allows viewing and modifying potentially sensitive configuration data on the target system. A patch is expected to be available via HPE support.

Affected products

  • HPE Networking SD-WAN Orchestrator

Timeline

  • 2026-08-04: disclosed

References

Related threats