← Vulnerability feed

Vulnerability record · CVE-2021-35218 · published 1 September 2021

CVE-2021-35218: SolarWinds Orion Platform Web Console deserialization RCE

Solarwinds · Orion Platform

The Web Console Chart endpoint in SolarWinds Orion Platform deserializes untrusted data, allowing remote code execution. An attacker with network access to the Patch Manager Web Console can exploit this to compromise the server. The flaw is a classic CWE-502 unsafe deserialization issue in a network-facing component.

8.8 CVSS 3.1 High EPSS 76% · top 0.5% CWE-502 · Deserialization of untrusted data
8.8CVSS 3.1 base score, v2 6.5
76%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Deserialization of Untrusted Data in the Web Console Chart Endpoint can lead to remote code execution. An unauthorized attacker who has network access to the Orion Patch Manager Web Console could potentially exploit this and compromise the server

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityNetwork-reachable deserialization leading to RCE with high EPSS and public technical detail, though not in KEV and requiring low privileges.

What it is

The Web Console Chart endpoint in SolarWinds Orion Platform deserializes untrusted data, allowing remote code execution. An attacker with network access to the Patch Manager Web Console can exploit this to compromise the server. The flaw is a classic CWE-502 unsafe deserialization issue in a network-facing component.

Impact

Successful exploitation lets an attacker execute arbitrary code on the Orion server, leading to full compromise of the host and potentially the broader management environment. Confidentiality, integrity and availability are all rated high.

Attack surface

Reached over the network via the Web Console Chart endpoint; the CVSS vector indicates low privileges are required (PR:L) and no user interaction (UI:N). The description calls the attacker unauthorized, so the practical requirement is network access plus whatever low-privilege access the endpoint accepts.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented. EPSS is very high (0.764, 99.5th percentile), and references include a ZDI advisory, indicating public technical detail exists, but the record does not confirm active exploitation.

What to do

  • Apply the vendor patch referenced in the SolarWinds Patch Manager 2020.2.6 release notes and trust-center advisory for CVE-2021-35218.
  • Restrict network access to the Orion Patch Manager Web Console to trusted management networks and administrative hosts.
  • Enforce least privilege on accounts that can reach the Web Console and remove unnecessary low-privilege access.
  • Monitor and, where feasible, block deserialization-heavy requests to the Chart endpoint at the web tier or WAF.
  • Review the ZDI-21-1248 advisory for additional vendor-recommended hardening.

Detection

  • Alert on anomalous or unexpected POST/GET requests to the Web Console Chart endpoint, especially from non-administrative sources.
  • Monitor Orion server processes for unexpected child processes or command execution spawned by the web console.
  • Watch for outbound connections from the Orion server to unfamiliar hosts that could indicate post-exploitation activity.
  • Correlate web console access logs with authentication events to spot low-privilege accounts touching the Chart endpoint.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-35218 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-10148SolarWinds Orion API authentication bypass allows remote command executionThe SolarWinds Orion Platform API contains an authentication bypass (CWE-288/CWE-306) that lets a remote, unauthenticated attacker execute API comman…KEVEPSS 92%analysed9.8CVE-2021-27258Solarwinds orion platform improper access control vulnerabilityThis vulnerability allows remote attackers to execute escalate privileges on affected installations of SolarWinds Orion Platform 2020.2. Authenticati…EPSS 4.0%9.8CVE-2021-25274Solarwinds orion platform deserialization of untrusted data vulnerabilityThe Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set permissions on its private que…EPSS 36%9.8CVE-2019-9546Solarwinds orion platform uncontrolled search path element vulnerabilitySolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation through the RabbitMQ service.EPSS 2.8%9.6CVE-2021-35222Solarwinds orion platform cross-site scripting vulnerabilityThis vulnerability allows attackers to impersonate users and perform arbitrary actions leading to a Remote Code Execution (RCE) from the Alerts Setti…EPSS 2.6%9.0CVE-2020-13169Solarwinds orion platform cross-site scripting vulnerabilityStored XSS (Cross-Site Scripting) exists in the SolarWinds Orion Platform before before 2020.2.1 on multiple forms and pages. This vulnerability may …EPSS 2.2%8.8CVE-2022-36960Solarwinds orion platform improper input validation vulnerabilitySolarWinds Platform was susceptible to Improper Input Validation. This vulnerability allows a remote adversary with valid access to SolarWinds Web Co…EPSS 0.91%8.8CVE-2022-36964Solarwinds orion platform deserialization of untrusted data vulnerabilitySolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with valid access to Solar…EPSS 17%

Source: NIST National Vulnerability Database (record CVE-2021-35218), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.