CVE-2026-63456

Hewlett Packard Enterprise (HPE) · EdgeConnect SD-WAN Orchestrator

Multiple vulnerabilities in the HPE EdgeConnect SD-WAN Orchestrator REST API allow unauthenticated remote attackers to bypass authentication and modify sensitive system information.

Executive summary

A critical authentication bypass vulnerability in the HPE EdgeConnect SD-WAN Orchestrator allows unauthenticated remote attackers to gain unauthorized access to system functions and data.

Vulnerability

This flaw exists within the REST API interface, where insufficient validation allows unauthenticated users to bypass authentication mechanisms. The attacker can interact with the API to view or manipulate system data without providing valid credentials.

Business impact

The CVSS score of 9.8 reflects the high severity of this vulnerability, as it allows full unauthorized access to the orchestration layer of the network. Successful exploitation could lead to the complete compromise of SD-WAN configuration, interception of network traffic, or the injection of malicious routing rules, resulting in significant operational disruption and data leakage.

Remediation

Immediate Action: Update the HPE EdgeConnect SD-WAN Orchestrator to the latest version provided by the vendor to implement proper authentication checks.

Proactive Monitoring: Review system access logs for unusual API activity or unauthorized requests targeting the REST interface.

Compensating Controls: Implement strict network access control lists (ACLs) to restrict access to the Orchestrator API to known, trusted management IP addresses only.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the critical CVSS score and the potential for full system compromise, organizations should prioritize patching this vulnerability immediately. Ensure that the Orchestrator management interface is not exposed to the public internet and restrict administrative access strictly to authorized internal segments.