Summary
CVE-2026-63455 is a critical authentication bypass affecting the REST API interface of HPE Networking (EdgeConnect) SD-WAN Orchestrator. Multiple flaws allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. HPE rates the issue CVSS 9.8 (Critical).
Technical details
- Root cause: Missing authentication for critical function (CWE-306) in the Orchestrator REST API interface, permitting authentication to be bypassed via spoofed HTTP headers.
- Trigger conditions: An attacker sends crafted requests to the network-reachable REST API; no valid credentials, prior authentication, or user interaction is required.
- Attack vector: Network (remote), low complexity, unauthenticated.
- Impact: Bypass of web authentication and access to protected system functions, with high impact to confidentiality, integrity, and availability of the Orchestrator.
Affected software
- HPE EdgeConnect SD-WAN Orchestrator 9.6.2.00000 up to and including 9.6.2.40208
- HPE EdgeConnect SD-WAN Orchestrator 9.6.3.00000 up to and including 9.6.3.40137
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Upgrade to a fixed release above the affected ranges as identified in HPE security bulletin HPESBNW05100 — a build later than 9.6.2.40208 for the 9.6.2 branch, and later than 9.6.3.40137 for the 9.6.3 branch.
- If no patch can be applied yet: Restrict network access to the Orchestrator management and REST API interface, limiting reachability to trusted management networks and removing exposure to the public internet until the update is deployed.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
Content-Security-Policyresponse header:silverpeaksystems.net,portal.silverpeak.cloud- Raw response body:
Welcome to SD-WAN Orchestrator

