Summary
CVE-2026-63455 is a critical authentication bypass affecting the REST API interface of HPE Networking (EdgeConnect) SD-WAN Orchestrator. Multiple flaws allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. HPE rates the issue CVSS 9.8 (Critical).
Technical details
- Root cause: Missing authentication for critical function (CWE-306) in the Orchestrator REST API interface, permitting authentication to be bypassed via spoofed HTTP headers.
- Trigger conditions: An attacker sends crafted requests to the network-reachable REST API; no valid credentials, prior authentication, or user interaction is required.
- Attack vector: Network (remote), low complexity, unauthenticated.
- Impact: Bypass of web authentication and access to protected system functions, with high impact to confidentiality, integrity, and availability of the Orchestrator.
Affected software
- HPE EdgeConnect SD-WAN Orchestrator 9.6.2.00000 up to and including 9.6.2.40208
- HPE EdgeConnect SD-WAN Orchestrator 9.6.3.00000 up to and including 9.6.3.40137
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Upgrade to a fixed release above the affected ranges as identified in HPE security bulletin HPESBNW05100 — a build later than 9.6.2.40208 for the 9.6.2 branch, and later than 9.6.3.40137 for the 9.6.3 branch.
- If no patch can be applied yet: Restrict network access to the Orchestrator management and REST API interface, limiting reachability to trusted management networks and removing exposure to the public internet until the update is deployed.

