← Vulnerability feed

Vulnerability record · CVE-2017-11467 · published 20 July 2017

CVE-2017-11467: OrientDB privilege bypass in where/fetchplan/order by leads to OS command execution

Orientdb · Orientdb

OrientDB through 2.2.22 fails to enforce privilege requirements when the where, fetchplan, or order by clauses are used, letting a remote attacker bypass authorization checks. Because the bypass reaches command execution paths, it allows arbitrary OS command execution on the database host. This is a critical pre-auth flaw in a database server that often holds sensitive data and runs with elevated service privileges.

9.8 CVSS 3.0 Critical EPSS 73% · top 0.6% CWE-269 · Improper privilege management
9.8CVSS 3.0 base score, v2 10.0
73%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

OrientDB through 2.2.22 does not enforce privilege requirements during "where" or "fetchplan" or "order by" use, which allows remote attackers to execute arbitrary OS commands via a crafted request.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated remote OS command execution with a CVSS of 9.8 and very high EPSS makes this an urgent patch-or-isolate case.

What it is

OrientDB through 2.2.22 fails to enforce privilege requirements when the where, fetchplan, or order by clauses are used, letting a remote attacker bypass authorization checks. Because the bypass reaches command execution paths, it allows arbitrary OS command execution on the database host. This is a critical pre-auth flaw in a database server that often holds sensitive data and runs with elevated service privileges.

Impact

An unauthenticated remote attacker can execute arbitrary operating system commands on the OrientDB server, leading to full host compromise, data theft, and lateral movement into connected systems.

Attack surface

Reachable over the network via crafted requests to the OrientDB service; the CVSS vector shows no privileges required and no user interaction, so no authentication is needed.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.73, 99.4th percentile) and a public exploit reference is tagged, indicating active interest and available exploit code.

What to do

  • Upgrade OrientDB to 2.2.23 or later, which the vendor release notes indicate fixes this issue.
  • If immediate upgrade is not possible, restrict network access to OrientDB ports to trusted hosts only and never expose the service to the internet.
  • Run the OrientDB service under a low-privilege dedicated account to limit the impact of command execution.
  • Audit database users and privileges, and remove or disable unused accounts and remote interfaces.
  • Monitor vendor advisories for further guidance and apply any additional hardening recommended for the 2.2.x line.

Detection

  • Inspect OrientDB server logs for requests containing where, fetchplan, or order by clauses with unusual or shell-like payloads.
  • Monitor for unexpected child processes spawned by the OrientDB service account (for example shells, curl, wget, or scripting interpreters).
  • Alert on outbound network connections originating from the database host to unfamiliar destinations.
  • Review file integrity and command history on OrientDB hosts for signs of post-exploitation activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-11467 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2015-2912Orientdb cross-site request forgery vulnerabilityThe JSONP endpoint in the Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 does not properly restrict callb…EPSS 1.3%6.1CVE-2015-2918Orientdb improper input validation vulnerabilityThe Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 does not properly restrict use of FRAME elements, whic…EPSS 0.74%5.9CVE-2015-2913Orientdb information exposure vulnerabilityserver/network/protocol/http/OHttpSessionManager.java in the Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1…EPSS 1.9%5.3CVE-2019-25447Orientdb cross-site request forgery vulnerabilityOrientDB 3.0.17 GA Community Edition contains cross-site request forgery vulnerabilities that allow attackers to perform unauthorized actions by craf…EPSS 0.14%5.1CVE-2019-25448Orientdb cross-site scripting vulnerabilityOrientDB 3.0.17 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by creating user…EPSS 0.26%5.1CVE-2019-25449Orientdb cross-site scripting vulnerabilityOrientDB 3.0.17 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by submitting crafted JSON …EPSS 0.23%9.9CVE-2026-84869ScreenConnect client allows unauthorized file transfer and execution in remote sessionsA flaw in the ConnectWise ScreenConnect client lets files be transferred and executed inside an active remote session without authorization or Host c…KEVEPSS 0.92%analysed9.8CVE-2026-46817Oracle E-Business Suite Payments missing authentication allows takeoverOracle Payments in Oracle E-Business Suite 12.2.3 through 12.2.15 contains an easily exploitable flaw in the File Transmission component. An unauthen…KEVEPSS 0.81%analysed

Source: NIST National Vulnerability Database (record CVE-2017-11467), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.