Hewlett Packard EnterpriseCVE-2026-63455
Hewlett Packard Enterprise EdgeConnect: information disclosure
Critical9.8CVE-2026-63455 · Published Aug 4, 2026 · updated Aug 6, 2026
Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify potentially sensitive information on the target system.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| EdgeConnect SD-WAN Orchestrator Product | >= 9.6.2.00000, <= 9.6.2.40208 | No fix yet |
| >= 9.6.3.00000, <= 9.6.3.40137 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-306
More Hewlett Packard Enterprise advisories
All Hewlett Packard Enterprise| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 5 | Hewlett Packard Enterprise HPE Integrated Lights-Out 6: denial of service | Medium6.5 | 1.78 |
| Aug 4 | Hewlett Packard Enterprise EdgeConnect: information disclosure | Critical9.8 | No fix yet |
| Jul 21 | Hewlett Packard Enterprise EdgeConnect SD-WAN Gateway: insecure permissions | High7.2 | No fix yet |
| Jul 21 | Hewlett Packard Enterprise EdgeConnect SD-WAN Gateway (ECOS): command injection | High7.2 | No fix yet |
| Jul 21 | Hewlett Packard Enterprise AOS-CX: buffer overflow | High7.2 | 10.18.0001 |
| Jul 21 | Hewlett Packard Enterprise AOS-CX: path traversal | High7.2 | 10.18.0001 |