← Back to browse · API

CVE-2021-27258

Severity
CRITICAL
CVSS
9.8
EPSS
0.03981
Risk score
40.59
CISA KEV
No
PoC
No
Published
2021-04-14
Modified
2024-08-03
First seen
2026-08-08
Aliases
EUVD-2021-14023, GHSA-3FP3-2JWC-WXVV
Products
SolarWinds:Orion Platform 2020.2
Sources
euvd EUVD-2021-14023

Description

This vulnerability allows remote attackers to execute escalate privileges on affected installations of SolarWinds Orion Platform 2020.2. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SaveUserSetting endpoint. The issue results from improper restriction of this endpoint to unprivileged users. An attacker can leverage this vulnerability to escalate privileges their privileges from Guest to Administrator. Was ZDI-CAN-11903.

References