← Back to browse · API

CVE-2020-10148

Severity
CRITICAL
CVSS
9.8
EPSS
0.9198
Risk score
57.19
CISA KEV
Yes
PoC
No
Published
2020-12-29
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2020-2611, GHSA-7C8F-5R89-MJGX
Products
SolarWinds:Orion, SolarWinds:Orion Platform 2019.4 HF 5, SolarWinds:Orion Platform 2020.2 HF 1, SolarWinds:Orion Platform 2020.2 without hotfix
Sources
cisa.gov CVE-2020-10148
euvd EUVD-2020-2611

Description

The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authentication and execute API commands which may result in a compromise of the SolarWinds instance. SolarWinds Orion Platform versions 2019.4 HF 5, 2020.2 with no hotfix installed, and 2020.2 HF 1 are affected.

References