Back

CRITICAL KEV

SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands

Published Dec 29, 2020 ·Due May 3, 2022

Description

The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authentication and execute API commands which may result in a compromise of the SolarWinds instance. SolarWinds Orion Platform versions 2019.4 HF 5, 2020.2 with no hotfix installed, and 2020.2 HF 1 are affected.

Affected products

Remediation

Vendor solution

Users should update to the relevant versions of the SolarWinds Orion Platform:

2019.4 HF 6 (released December 14, 2020) 2020.2.1 HF 2 (released December 15, 2020) 2019.2 SUPERNOVA Patch (released December 23, 2020) 2018.4 SUPERNOVA Patch (released December 23, 2020) 2018.2 SUPERNOVA Patch (released December 23, 2020)

Metrics

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner certcc
Published Dec 29, 2020
Updated Oct 21, 2025
Reserved Mar 5, 2020
CISA Vulnrichment
Updated Aug 1, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a