Executive brief
HPE Networking SD-WAN Orchestrator is a centralized management platform for software-defined wide-area networks used by enterprises to optimize network traffic. A vulnerability in its REST API allows unauthenticated attackers to bypass authentication and gain unauthorized access to the system, enabling them to read and modify sensitive network configuration and operational data without credentials.
Technical details
Multiple vulnerabilities exist in the REST API interface of HPE Networking SD-WAN Orchestrator that permit unauthenticated remote attackers to circumvent web authentication mechanisms. The vulnerabilities enable attackers on the network to directly invoke protected system functions and access sensitive information through API endpoints. The attack requires network reachability to the REST API interface but no prior authentication or user interaction. Successful exploitation allows viewing and modifying potentially sensitive configuration data on the target system. A patch is expected to be available via HPE support.
Affected products
- HPE Networking SD-WAN Orchestrator
Timeline
- 2026-08-04: disclosed