The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authentication and execute API commands which may result in a compromise of the SolarWinds instance. SolarWinds Orion Platform versions 2019.4 HF 5, 2020.2 with no hotfix installed, and 2020.2 HF 1 are affected.
Advisories

No advisories yet.

Fixes

Solution

Users should update to the relevant versions of the SolarWinds Orion Platform: 2019.4 HF 6 (released December 14, 2020) 2020.2.1 HF 2 (released December 15, 2020) 2019.2 SUPERNOVA Patch (released December 23, 2020) 2018.4 SUPERNOVA Patch (released December 23, 2020) 2018.2 SUPERNOVA Patch (released December 23, 2020)


Workaround

No workaround given by the vendor.

History

Wed, 22 Oct 2025 00:30:00 +0000


Tue, 21 Oct 2025 20:30:00 +0000


Tue, 21 Oct 2025 19:30:00 +0000


Mon, 17 Mar 2025 20:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287 CWE-306

cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2025-10-21T23:35:30.955Z

Reserved: 2020-03-05T00:00:00.000Z

Link: CVE-2020-10148

cve-icon Vulnrichment

Updated: 2024-08-04T10:50:57.882Z

cve-icon NVD

Status : Modified

Published: 2020-12-29T22:15:12.327

Modified: 2025-10-22T00:16:53.907

Link: CVE-2020-10148

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.