Executive brief
HPE Networking SD-WAN Orchestrator is a centralized management platform for SD-WAN networks. Multiple vulnerabilities in its REST API allow unauthenticated attackers to bypass authentication and access or modify sensitive system data. A successful exploit could result in unauthorized access to network configuration, credentials, and customer data.
Technical details
The REST API interface in HPE Networking SD-WAN Orchestrator contains multiple vulnerabilities that enable authentication bypass without credentials. An unauthenticated attacker with network access to the REST API can exploit these flaws to bypass web authentication mechanisms and directly access system functions. The vulnerabilities allow an attacker to view and modify potentially sensitive information stored on the target system, including network configurations and system data. No user interaction is required. Patches should be available from HPE for affected versions.
Affected products
- HPE Networking SD-WAN Orchestrator
Timeline
- 2026-08-04: disclosed