Critical Authentication Bypass in SolarWinds Orion API (CVE-2020-10148)

Critical Authentication Bypass in SolarWinds Orion API (CVE-2020-10148)

First seen 17 Jun 2026, 12:42 UTC nvd.nist.govRapid7www.solarwinds.comkb.cert.org 85% similarity 72.6

Article Content

Browse articles
ThreatCluster

The SolarWinds Orion API is vulnerable to an authentication bypass, allowing remote attackers to execute API commands without authentication. This vulnerability, identified as CVE-2020-10148, can be exploited by appending specific parameters to the Request.PathInfo portion of a URI request. Affected versions include SolarWinds Orion Platform versions 2019.4 HF 5, 2020.2 with no hotfix, and 2020.2 HF 1. The vulnerability has been actively exploited in the wild, and organizations are urged to update to patched versions released in December 2020. The flaw is linked to the installation of the SUPERNOVA malware. Security advisories and mitigations have been issued, including hardening IIS servers. Users are encouraged to apply updates promptly to protect their systems.

Key Points: • CVE-2020-10148 allows unauthenticated remote code execution via SolarWinds Orion API. • Affected versions include 2019.4 HF 5 and 2020.2 without hotfixes. • Immediate patching is critical due to active exploitation of this vulnerability.

ThreatCluster AI How this analysis works

Timeline

2020-12-29
CVE-2020-10148 published
The vulnerability was officially published, detailing the authentication bypass in SolarWinds Orion API.
nvd.nist.gov
2021-01-05
First public PoC released
The first proof of concept for exploiting CVE-2020-10148 was made public, increasing the risk of attacks.
nvd.nist.gov
2021-11-03
CVE added to CISA KEV
CISA added CVE-2020-10148 to its Known Exploited Vulnerabilities catalog due to active exploitation.
nvd.nist.gov
Recent
SolarWinds updates security advisory
SolarWinds updated their advisory to track critical security issues in the Orion platform, including CVE-2020-10148.
Rapid7

Community

Browse all →