Multiple vulnerabilities have been identified in the Hewlett Packard Enterprise (HPE) EdgeConnect SD-WAN Orchestrator. The vulnerabilities are of the authentication bypass type, allowing an unauthenticated remote attacker to bypass web authentication on the REST API. This poses a significant business risk, as a successful attack could grant an attacker wide reach and allow them to view and modify sensitive information on the target system.
CVE-2026-63455 (CVSS 9.8 — Critical): This vulnerability allows an attacker to bypass authentication on the REST API by spoofing HTTP headers, requiring no credentials and allowing for remote exploitation with low complexity. An attacker could exploit this vulnerability to gain unauthorized access to the system.[/subscribe_to_unlock_form]
Multiple vulnerabilities have been identified in the Hewlett Packard Enterprise (HPE) EdgeConnect SD-WAN Orchestrator. The vulnerabilities are of the authentication bypass type, allowing an unauthenticated remote attacker to bypass web authentication on the REST API. This poses a significant business risk, as a successful attack could grant an attacker wide reach and allow them to view and modify sensitive information on the target system.
CVE-2026-63455 (CVSS 9.8 — Critical): This vulnerability allows an attacker to bypass authentication on the REST API by spoofing HTTP headers, requiring no credentials and allowing for remote exploitation with low complexity. An attacker could exploit this vulnerability to gain unauthorized access to the system.[emaillocker id="1283"]
CVE-2026-63456 (CVSS 9.8 — Critical): A critical improper authentication vulnerability in the REST API interface of HPE Networking SD-WAN Orchestrator allows an unauthenticated remote attacker to bypass web authentication mechanisms and access or modify potentially sensitive system information.
The following reports contain further technical details:
[/emaillocker]