CVE-2026-63455 / CVE-2026-63456 — HPE Aruba Networking SD-WAN Orchestrator: spoofed HTTP headers bypass REST API authentication (CVSS 9.8), with the vendor and CERT-FR scoping the affected branches differently
HPE Aruba Networking published HPESBNW05100 on 2026-08-04 for two vulnerabilities in the REST API interface of its SD-WAN Orchestrator, describing them as authentication bypass via spoofed HTTP headers that could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions, with successful exploitation permitting an attacker to view and modify potentially sensitive information on the target system (HPE Aruba Networking, 2026-08-04). Both carry CVSS v3.1 9.8 on the vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, and the vendor scopes the exposure tightly: only the 9.6.x software branch is affected, specifically 9.6.2.x builds at 9.6.2.40208 and below and 9.6.3.x builds at 9.6.3.40137 and below, with no branches outside 9.6.x.x affected at all (HPE Aruba Networking, 2026-08-04). Both were reported through HPE Aruba's bug-bounty programme, and the vendor states it is not aware of any public discussion or exploit code targeting them as of the advisory's release (HPE Aruba Networking, 2026-08-04). CERT-FR carried the advisory to its constituency the next day, but scopes it wider: its systems-affected list adds EdgeConnect SD-WAN Orchestrator 9.7.0.x builds below 9.7.0.43264 alongside the two 9.6.x branches (CERT-FR, 2026-08-05). The vendor is authoritative for its own product and the recommended upgrade target is unchanged either way, but an operator sitting on a 9.7.0 build below 9.7.0.43264 should know that one of the two advisories covering these CVEs places them inside the affected set.
The reason this is worth acting on ahead of the routine cycle is not the score but the class and the company it keeps. An SD-WAN Orchestrator is the control plane for an organisation's wide-area network — the system that pushes policy and configuration to every branch appliance — so authentication bypass on its API is reach into the network fabric rather than into one host. This lands in the same short window in which a directly comparable product, Arista's on-premises VeloCloud Orchestrator, was confirmed exploited through an unauthenticated command injection on an interface exposed by default (covered here on 2026-07-28). Nothing in the HPE Aruba advisory connects the two, and this entry does not: the point is that attacker attention is demonstrably on this product class right now, which is an argument for treating the exposure question as urgent even while exploitation of these particular CVEs remains unreported.
Defender actions
- Move any SD-WAN Orchestrator below 9.6.2.40210, 9.6.3.40140 or 9.7.0.43264 to one of those builds — and include 9.7.0.x instances below 9.7.0.43264 in that sweep even though HPE's advisory scopes them out, because CERT-FR's advisory on the same CVEs scopes them in and the upgrade target is identical; if the change window is further out, apply HPE Aruba's own interim control and confine the Orchestrator CLI and web management interfaces to a dedicated VLAN or firewall policy.
ATT&CK mapping
1 technique mapped from the cited reporting · MITRE ATT&CK v19.1
Initial Access TA0001
T1190Exploit Public-Facing Application
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.