


Perceptive Security
SOC/SIEM Consultancy

Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentica…
Published:
3 August 2026 at 22:00:00
Alert date:
4 August 2026 at 18:03:19
Source:
nvd.nist.gov
Network Infrastructure, Identity & Access, Zero-Day Vulnerabilities
Multiple vulnerabilities have been identified in the REST API interface of HPE Networking SD-WAN Orchestrator. An unauthenticated remote attacker could exploit these flaws to bypass web authentication mechanisms and gain access to system functions. Successful exploitation may allow the attacker to view and modify potentially sensitive information on the target system. The vulnerabilities are classified as high severity given the unauthenticated nature of the attack vector and the scope of access granted. HPE has published a security bulletin with further details and remediation guidance. Organizations using HPE Networking SD-WAN Orchestrator should apply patches or mitigations promptly. The vulnerability is tracked under CVE-2026-63456 and is listed in the NVD database.
Technical details
Mitigation steps:
Affected products:
HPE Networking SD-WAN Orchestrator
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-63456
https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05100en_us&docLocale=en_US
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
