


Perceptive Security
SOC/SIEM Consultancy

Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentica…
Published:
3 August 2026 at 22:00:00
Alert date:
4 August 2026 at 18:03:19
Source:
nvd.nist.gov
Network Infrastructure, Identity & Access, Web Technologies
Multiple vulnerabilities have been identified in the REST API interface of HPE Networking SD-WAN Orchestrator. These flaws could allow an unauthenticated remote attacker to bypass web authentication mechanisms and gain unauthorized access to system functions. Successful exploitation may enable attackers to view and modify potentially sensitive information on the affected system. The vulnerabilities are tracked under CVE-2026-63455 and are published via the NVD. HPE has issued a security bulletin providing further details and remediation guidance. The severity is rated High given the unauthenticated remote exploitation potential and the impact on confidentiality and integrity.
Technical details
Mitigation steps:
Affected products:
HPE Networking SD-WAN Orchestrator
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-63455
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05100en_us&docLocale=en_US
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
