Executive brief
HPE's SD-WAN Orchestrator is software that manages and orchestrates software-defined wide-area networks for enterprise connectivity. An authenticated attacker with minimal read-only privileges can extract sensitive third-party API tokens and credentials by sending a crafted request to a cache endpoint, enabling them to compromise integrated security platforms and move laterally across the organization's infrastructure.
Technical details
An information disclosure vulnerability in the SD-WAN Orchestrator's cache synchronization endpoint allows authenticated users with read-only privileges to retrieve sensitive credentials and API tokens through a specially crafted request. The vulnerability does not require elevated privileges or user interaction; authentication alone is sufficient. Successful exploitation exposes third-party API credentials, creating a path for lateral movement to external security systems.
Affected products
- HPE SD-WAN Orchestrator
Timeline
- 2026-09-15: disclosed