CVE-2026-63455

Aruba EdgeConnect: Sicherheitsluecke

criticalEPSS 0.8%

Affected

  • Aruba/EdgeConnect SD-WAN Orchestrator 9.7.0.43264..*
  • Aruba/EdgeConnect SD-WAN Orchestrator 9.6.3.40140..*
  • Aruba/EdgeConnect SD-WAN Orchestrator 9.6.2.40210..*

Description

Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify potentially sensitive information on the target system.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

ArubaEdgeConnect
SD-WAN Orchestrator 9.6.2.40210SD-WAN Orchestrator 9.6.3.40140SD-WAN Orchestrator 9.7.0.43264

Metrics

9.8
Source: nvd-v3
55.2 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
critical
no public PoC known
0.8 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-08-04 16:40 UTC

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. New CVE Received2026-08-04 17:16 UTC· security-alert@hpe.com
    • Affected: EdgeConnect SD-WAN Orchestrator
    • Description: Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify potentially sensitive information on the target system.
    • CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    • Reference: https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05100en_us&docLocale=en_US

Linked advisories