VYPR
Unrated severityNVD Advisory· Published Aug 4, 2026· Updated Aug 4, 2026

Authentication bypass via spoofed HTTP headers Orchestrator REST API

CVE-2026-63455

Description

Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify potentially sensitive information on the target system.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.