TL;DR
HPE Aruba Networking patched two critical flaws in its SD-WAN EdgeConnect Orchestrator. Both carry a CVSS score of 9.8. They let an unauthenticated remote attacker bypass web authentication on the REST API. HPE reports no known exploitation so far.
- Product: Hewlett Packard Enterprise (HPE) EdgeConnect SD-WAN Orchestrator
- Vulnerabilities: 2 flaws (CVE-2026-63455, CVE-2026-63456)
- Highest severity: 9.8 (Critical · CVSSv3)
- Worst impact: Authentication bypass via spoofed HTTP headers Orchestrator REST API
- Status: No confirmed exploitation yet
- Action: See vendor advisories
| CVE | CVSS (CVSSv3) | Type | Status |
|---|---|---|---|
| CVE-2026-63455 | 9.8 | CWE-306 | Not exploited |
| CVE-2026-63456 | 9.8 | CWE-287 | Not exploited |
Why it matters
An Orchestrator controls an entire SD-WAN fabric. Therefore a full authentication bypass hands an attacker wide reach. HPE warns that a successful attacker “could view and modify potentially sensitive information on the target system.”
How the attack works
The EdgeConnect Orchestrator authentication bypass lives in the REST API interface. According to HPE’s advisory, an attacker spoofs HTTP headers to trick the API. That trick skips the normal web authentication check.
No credentials are needed. The flaw scores AV:N/AC:L/PR:N/UI:N, so the attack runs remotely with low complexity. As a result, both CVE-2026-63455 and CVE-2026-63456 earned the 9.8 rating.
Exploitation status
HPE Aruba Networking states it is “not aware of any public discussion or exploit code targeting these specific vulnerabilities” as of the advisory date. No proof-of-concept has surfaced publicly.
Affected versions
Only the 9.6.x branch is affected. That includes 9.6.2.x builds up to 9.6.2.40208 and 9.6.3.x builds up to 9.6.3.40137. Branches outside 9.6.x are not affected.
Patch and mitigation
Admins should upgrade now. Fixed builds include 9.6.2.40210, 9.6.3.40140, and 9.7.0.43264 or later. Until you patch, restrict management interfaces to a dedicated VLAN and apply firewall rules.
HPE also advises IP allow-listing for local users and API keys. Full details appear in the HPE Aruba Networking security advisory HPESBNW05100.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!