2026-08-06 · view entry permalink →
CVE-2026-63455 / CVE-2026-63456 — HPE Aruba Networking SD-WAN Orchestrator: spoofed HTTP headers bypass REST API authentication (CVSS 9.8), with the vendor and CERT-FR scoping the affected branches differently
HPE Aruba Networking published HPESBNW05100 on 2026-08-04 for two vulnerabilities in the REST API interface of its SD-WAN Orchestrator, describing them as authentication bypass via spoofed HTTP headers that could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions, with successful exploitation permitting an attacker to view and modify potentially sensitive information on the target system (HPE Aruba Networking, 2026-08-04). Both carry CVSS v3.1 9.8 on the vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, and the vendor scopes the exposure tightly: only the 9.6.x software branch is affected, specifically 9.6.2.x builds at 9.6.2.40208 and below and 9.6.3.x builds at 9.6.3.40137 and below, with no branches outside 9.6.x.x affected at all (HPE Aruba Networking, 2026-08-04). Both were reported through HPE Aruba's bug-bounty programme, and the vendor states it is not aware of any public discussion or exploit code targeting them as of the advisory's release (HPE Aruba Networking, 2026-08-04). CERT-FR carried the advisory to its constituency the next day, but scopes it wider: its systems-affected list adds EdgeConnect SD-WAN Orchestrator 9.7.0.x builds below 9.7.0.43264 alongside the two 9.6.x branches (CERT-FR, 2026-08-05). The vendor is authoritative for its own product and the recommended upgrade target is unchanged either way, but an operator sitting on a 9.7.0 build below 9.7.0.43264 should know that one of the two advisories covering these CVEs places them inside the affected set.
The reason this is worth acting on ahead of the routine cycle is not the score but the class and the company it keeps. An SD-WAN Orchestrator is the control plane for an organisation's wide-area network — the system that pushes policy and configuration to every branch appliance — so authentication bypass on its API is reach into the network fabric rather than into one host. This lands in the same short window in which a directly comparable product, Arista's on-premises VeloCloud Orchestrator, was confirmed exploited through an unauthenticated command injection on an interface exposed by default (covered here on 2026-07-28). Nothing in the HPE Aruba advisory connects the two, and this entry does not: the point is that attacker attention is demonstrably on this product class right now, which is an argument for treating the exposure question as urgent even while exploitation of these particular CVEs remains unreported.