-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 HPE Aruba Networking Product Security Advisory ============================================== Advisory ID: HPESBNW05100 CVE: CVE-2026-63455, CVE-2026-63456 Publication Date: 2026-AUG-4 Status: FINAL Severity: CRITICAL Revision: 1 Title ===== Multiple Vulnerabilities in HPE Aruba Networking SD-WAN Orchestrator 9.6.x Software Branch Only Overview ======== HPE Aruba Networking has released patches for HPE Networking SD-WAN Orchestrator that addresses multiple security vulnerabilities in 9.6.x Software branch. Affected Products ================= HPE Aruba Networking SD-WAN Orchestrator - SD-WAN Orchestrator 9.6.2.x: 9.6.2.40208 and below - SD-WAN Orchestrator 9.6.3.x: 9.6.3.40137 and below No branches outside of 9.6.x.x are affected by these vulnerabilities. Unaffected Products ================= Any other HPE Aruba Networking products not specifically listed above, are not affected by these vulnerabilities. Details ======= Authentication bypass via spoofed HTTP headers Orchestrator REST API (CVE-2026-63455, CVE-2026-63456) - --------------------------------------------------------------------- Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify potentially sensitive information on the target system. Internal References: VULN-633, VULN-585, VULN-578, VULN-577, VULN-576 Severity: CRITICAL CVSSv3.1 Base Score: 9.8 CVSSv3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Discovery: These vulnerabilities were discovered and reported by Christopher Alejandro (Moroco) through HPE Aruba Networking's Bug Bounty program Resolution ========== In order to address the vulnerabilities described above for the affected software branches, HPE Aruba Networking recommends upgrading the software to one of the following versions (as applicable): - SD-WAN Orchestrator 9.7.0.x: 9.7.0.43264 and above - SD-WAN Orchestrator 9.6.3.x: 9.6.3.40140 and above - SD-WAN Orchestrator 9.6.2.x: 9.6.2.40210 and above Software versions with resolution/fixes for the vulnerabilities covered above, can be downloaded from the HPE Networking Support Portal. https://networkingsupport.hpe.com/home/ Product software versions that have reached End of Maintenance (EoM) are presumed to be affected by the vulnerabilities unless explicitly stated otherwise, and are not covered by this security advisory. HPE Aruba Networking does not evaluate or patch software branches that have reached their End of Support (EoST) milestone. For more information about HPE Aruba Networking EdgeConnect Product Lifecycle Policy, please visit: https://arubanetworking.hpe.com/techdocs/sdwan-PDFs/docs/eula/EC_LifecyclePolicy_latest.pdf Workaround ========== To minimize the likelihood of an attacker exploiting these vulnerabilities, HPE Aruba Networking recommends that the CLI and web-based management interfaces be restricted to a dedicated layer 2 segment/VLAN and/or controlled by firewall policies at layer 3 and above along with accounting controls for tracking and logging user activities and resource usage. As a best practice, it is recommended to configure IP-allow-listing for Orchestrator local users and API keys. You may contact HPE Services - HPE Aruba Networking for assistance if needed. For more information, please visit HPE Aruba Networking Support Portal at https://networkingsupport.hpe.com/home Exploitation and Public Discussion ================================== HPE Aruba Networking is not aware of any public discussion or exploit code targeting these specific vulnerabilities as of the release date of the advisory. Revision History ================ Revision 1 / 2026-AUG-4 / Initial release HPE Aruba Networking SIRT Security Procedures ============================================== Complete information on reporting security vulnerabilities in HPE Aruba Networking products and obtaining assistance with security incidents is available at: http://www.hpe.com/support/security-response-policy For reporting NEW HPE Aruba Networking security issues, email can be sent to hpe-networking-sirt@hpe.com. For sensitive information we encourage the use of PGP encryption. Our public keys can be found at: https://www.hpe.com/info/psrt-pgp-key (c) Copyright 2026 by Hewlett Packard Enterprise Development LP. This advisory may be redistributed freely after the release date given at the top of the text, provided that the redistributed copies are complete and unmodified, including all data and version information. -----BEGIN PGP SIGNATURE----- iQHLBAEBCAA1FiEEQT1cq06WWXH+NEKru7x8adyj7A4FAmptFX0XHHNlY3VyaXR5 LWFsZXJ0QGhwZS5jb20ACgkQu7x8adyj7A4a4gv+JIbTGT03D5gB1qD2zV/55QvJ WYalVvfqmTuxlvXGa8xUH79d/bx/N/FYMlil8t8H9l7JStMQUDtCvZ5Yfy/y6QJ8 xbCKYpp7cpLs2CBZAFO74l7jEL9KTaZBCYOVzZ80sTZFBB8WWxGbiuimdwz9rqff L+iPtfLmCrOECWpnfFURiR59FfHY8cX/JCuwXCq7RDWByUYPExAbtbKG4Mx9xFn3 1JQ5Upow1vCRVuSacMsq4K8ien4zJIk/ezDBv1cnJDB9LYaW5xcr0a4MCAt0py+N EEQxpruGSCD8fRD3vm4iueXwL/IkCRUC0idnzJAM4421MFIV/aoo7YRIawyj6Wjz v4FUsoK4grzy4EI1n50SZHQ+s/XrU1yDTJXGZxfaEDVL5Q9897EIWeKz1APPm04L f1Kw6lFECIbzgIt/kzVgv2Ou2khOkMlo342lov5V6rzYl+DJ77WV4uI5fnuwhSgL tukCxy3KWPC/KOugdbuLxvMwh7YzsAsgEt4d1wek =Z9xY -----END PGP SIGNATURE-----