LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-10148: SolarWinds Orion Authentication Bypass Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-10148 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

SolarWinds Orion API contains an authentication bypass vulnerability that could allow a remote attacker to execute API commands.

CVE-2020-10148 is an authentication bypass vulnerability in the SolarWinds Orion platform’s API. A remote attacker who can reach the API may be able to invoke API commands without valid credentials. Because Orion is commonly used for network and systems monitoring, successful abuse can give an attacker a foothold into management infrastructure and the systems it oversees. Public detail is limited to the CISA description and the CWE classification; confirm exact impact, fixed builds, and configuration notes against the vendor advisory.

This guidance is for IT and security teams that need to inventory, detect, and reduce risk from this class of flaw. Known ransomware use is not documented for this CVE.

How it works

The weakness is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel). In products that expose management APIs, this class of flaw typically means some request path or interface fails to enforce the same authentication checks that protect the rest of the application. An attacker who can send requests to the Orion API may therefore reach command endpoints that should require login or token validation.

CISA summarizes the issue as: the SolarWinds Orion API contains an authentication bypass that could allow a remote attacker to execute API commands. Exact request patterns, required headers, or which API methods are reachable are not provided in the facts available here; treat any public proof-of-concept material with caution and verify behavior only in a controlled lab against the vendor’s description. The practical risk is unauthorized use of Orion’s management capabilities once the API is reachable without proper authentication.

Am I affected? How to find it in your systems

SolarWinds Orion is typically deployed as an on-premises or privately hosted monitoring suite used by network operations and IT teams. It often runs on Windows servers, may be multi-tier (web/API, application, database), and is frequently reachable from management networks or, if misconfigured, from broader internal or external networks.

How to remediate

Patch first. CISA’s required action is to apply updates per vendor instructions. Obtain the security update that addresses CVE-2020-10148 from SolarWinds, validate it in a test environment if your change process requires it, then deploy to production Orion instances and verify the service is healthy afterward.

If you can't patch immediately

Until the vendor update is applied, reduce exposure with compensating controls appropriate to an authentication-bypass on a management API.

These steps do not replace the patch; they only lower likelihood and impact until the update is installed.

If your data may have been exposed

Actively exploited authentication-bypass vulnerabilities on management platforms can lead to unauthorized access, configuration tampering, or lateral movement, and in some environments that path has contributed to broader incidents. Known ransomware use is not documented for this CVE, but absence of documentation is not proof of non-use. If Orion was internet-exposed or you see suspicious API activity in logs, treat the host and connected systems as potentially compromised: isolate as needed, preserve logs, hunt for persistence, and follow your incident-response process.

As a routine check for personal or work email addresses that may appear in third-party breach data, you can run a free exposure scan of your email to see whether it appears in known breach corpora and then prioritize password changes and MFA where relevant.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSolarWinds · Orion
WeaknessCWE-288
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities