CVE-2026-63456 Details
Description
Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify potentially sensitive information on the target system.
A vulnerability allowing authentication bypass via spoofed HTTP headers has been identified in the REST API of HPE Networking SD-WAN Orchestrator. This issue affects versions 9.6.2.x through 9.6.2.40208 and 9.6.3.x through 9.6.3.40137. The vulnerability could enable an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions, potentially leading to unauthorized viewing and modification of sensitive information on the target system.
Users are advised to upgrade to HPE Networking SD-WAN Orchestrator version 9.7.0.43264 and above, or version 9.6.3.40140 and above. For versions 9.6.2.x, upgrade to 9.6.2.40210 and above. These updates can be downloaded from the HPE Networking Support Portal.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05100en_us&docLocale=en_US | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | CISA-ADP |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 4, 2026 | CVE Modified | CISA-ADP |
| Aug 4, 2026 | New CVE Received | [email protected] |