Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4244 articles · 196959 vulns · 37/41 feeds (7d)
← Back to list
9.8
CVE-2026-63456
hewlett packard enterprise (hpe) · edgeconnect sd-wan orchestrator

Authentication bypass via spoofed HTTP headers Orchestrator REST API

Description

Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify potentially sensitive information on the target system.

Affected Products

VendorProductVersions
hewlett packard enterprise (hpe)edgeconnect sd-wan orchestrator9.6.2.00000, 9.6.3.00000

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
arubaedgeconnectcert_advisory90%

References

  • https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05100en_us&docLocale=en_US

Related News (3 articles)

Tier B
BSI Advisories20d ago
[NEU] [hoch] Aruba EdgeConnect SD-WAN Orchestrator: Mehrere Schwachstellen ermöglichen Umgehen von Sicherheitsvorkehrungen
→ No new info (linked only)
Tier B
CERT-FR20d ago
Multiples vulnérabilités dans HPE Aruba Networking EdgeConnect SD-WAN Orchestrator (05 août 2026)
→ No new info (linked only)
Tier C
VulDB20d ago
CVE-2026-63456 | HPE EdgeConnect SD-WAN Orchestrator REST API Interface improper authentication
→ No new info (linked only)
CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
PublishedAug 4, 2026
Trending Score7
Source articles3
Independent3
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-63455
Authentication bypass via spoofed HTTP headers Orchestrator REST API
Trending: 7
MEDIUMCVE-2026-63457
CVE-2026-63457: A potential denial of service vulnerability exists in HPE Integrated Lights-Out 6 (iLO 6) prior to v1.78.
Trending: 4
HIGHCVE-2026-63454
Authenticated Path Traversal Vulnerability Leads to Remote Code Execution in AOS-CX
Trending: 1
HIGHCVE-2026-63453
Authenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CX
Trending: 1
HIGHCVE-2026-44880
Low-Privilege Authenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CX
Trending: 1

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 4, 2026
Discovered by ZDM
Aug 4, 2026