Summary
CVE-2026-63456 is a critical authentication bypass vulnerability in the REST API interface of HPE EdgeConnect SD-WAN Orchestrator (HPE Networking SD-WAN Orchestrator). An unauthenticated remote attacker can bypass web authentication mechanisms and reach system functions, allowing them to view and modify sensitive system information. It carries a CVSS v3.1 base score of 9.8 (Critical).
Technical details
- Root cause: Improper authentication (CWE-287) in the product’s REST API interface.
- Trigger conditions: Reachable over the network with no authentication and no user interaction required.
- Attack vector: Network (remote), low attack complexity.
- Impact: Bypass of web authentication mechanisms enabling access to system functions, with the ability to view and modify sensitive system information (high confidentiality and integrity impact, and high availability impact).
Affected software
- HPE EdgeConnect SD-WAN Orchestrator 9.6.2.00000 through 9.6.2.40208
- HPE EdgeConnect SD-WAN Orchestrator 9.6.3.00000 through 9.6.3.40137
Severity
- CVSS v3.1 base score: 9.8 (Critical)
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Upgrade to a fixed release as directed in HPE advisory HPESBNW05100 — a build later than 9.6.2.40208 for the 9.6.2 branch, and later than 9.6.3.40137 for the 9.6.3 branch.
- If no patch: Restrict network access to the Orchestrator management and REST API interfaces so they are not reachable from untrusted networks or the public internet; limit access to trusted management networks and monitor for unauthorized access.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
Content-Security-Policyresponse header:silverpeaksystems.net,portal.silverpeak.cloud- Raw response body:
Welcome to SD-WAN Orchestrator

