Rapid7 Critical Authentication Bypass in SolarWinds Orion API (CVE-2020-10148)
Article Content
- •CVE-2020-10148 allows unauthenticated remote code execution via SolarWinds Orion API.
- •Affected versions include 2019.4 HF 5 and 2020.2 without hotfixes.
- •Immediate patching is critical due to active exploitation of this vulnerability.
The SolarWinds Orion API is vulnerable to an authentication bypass, allowing remote attackers to execute API commands without authentication. This vulnerability, identified as CVE-2020-10148, can be exploited by appending specific parameters to the Request.PathInfo portion of a URI request. Affected versions include SolarWinds Orion Platform versions 2019.4 HF 5, 2020.2 with no hotfix, and 2020.2 HF 1. The vulnerability has been actively exploited in the wild, and organizations are urged to update to patched versions released in December 2020. The flaw is linked to the installation of the SUPERNOVA malware. Security advisories and mitigations have been issued, including hardening IIS servers. Users are encouraged to apply updates promptly to protect their systems.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Raindrop, SolarWinds and CVE-2020-10148 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…