CVE-2026-63455
Aruba EdgeConnect: Sicherheitsluecke
criticalEPSS 0.8%
Affected
- Aruba/EdgeConnect
SD-WAN Orchestrator 9.7.0.43264..* - Aruba/EdgeConnect
SD-WAN Orchestrator 9.6.3.40140..* - Aruba/EdgeConnect
SD-WAN Orchestrator 9.6.2.40210..*
Description
Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify potentially sensitive information on the target system.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
ArubaEdgeConnect
SD-WAN Orchestrator 9.6.2.40210SD-WAN Orchestrator 9.6.3.40140SD-WAN Orchestrator 9.7.0.43264Metrics
Show all metrics
Severity
critical
97.53
no public PoC known
9.8
Published
2026-08-04 16:40 UTC
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- New CVE Received2026-08-04 17:16 UTC· security-alert@hpe.com
- Affected: EdgeConnect SD-WAN Orchestrator
- Description: Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify potentially sensitive information on the target system.
- CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Reference: https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05100en_us&docLocale=en_US