← Vulnerability feed

Vulnerability record · CVE-2022-36958 · published 20 October 2022

CVE-2022-36958: SolarWinds Platform Web Console deserialization allows remote command execution

Solarwinds · Orion Platform

SolarWinds Platform (Orion Platform) deserializes untrusted data, letting an attacker run arbitrary commands. The flaw is reachable remotely through the Web Console by a user who already holds valid credentials. Because it yields full command execution on a monitoring platform, it is a serious post-authentication compromise path.

8.8 CVSS 3.1 High EPSS 82% · top 0.4% CWE-502 · Deserialization of untrusted data
8.8CVSS 3.1 base score
82%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with valid access to SolarWinds Web Console to execute arbitrary commands.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityRemote code execution with high CIA impact and a very high EPSS score, though it requires valid credentials and is not in KEV.

What it is

SolarWinds Platform (Orion Platform) deserializes untrusted data, letting an attacker run arbitrary commands. The flaw is reachable remotely through the Web Console by a user who already holds valid credentials. Because it yields full command execution on a monitoring platform, it is a serious post-authentication compromise path.

Impact

An attacker with valid Web Console access gains arbitrary command execution on the SolarWinds server, with high impact to confidentiality, integrity and availability. This can lead to full control of the platform and any data or downstream systems it manages.

Attack surface

Reached over the network via the SolarWinds Web Console (CVSS AV:N). It requires low privileges (PR:L) and no user interaction (UI:N), so any valid low-privileged account is enough.

Exploitation

Not listed in CISA KEV and no ransomware use documented. EPSS is very high (0.82746, 99.65th percentile), and references are only vendor and ZDI advisories, so no public exploit code is confirmed in this record.

What to do

  • Apply the SolarWinds fix for CVE-2022-36958 from the vendor advisory as the first action.
  • Restrict and audit Web Console accounts; remove unused or over-privileged accounts and enforce least privilege.
  • Limit network access to the Web Console to trusted management networks rather than exposing it broadly.
  • Monitor and alert on suspicious child processes spawned by SolarWinds/Orion service processes.

Detection

  • Alert on unexpected child processes (cmd.exe, powershell.exe, /bin/sh) spawned by SolarWinds/Orion web or service processes.
  • Review Web Console authentication logs for anomalous logins or use of low-privileged accounts.
  • Hunt for deserialization-related errors or unusual HTTP POST bodies to Web Console endpoints in web and application logs.
  • Baseline normal SolarWinds process behavior and flag deviations in process lineage and network egress.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-36958 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-10148SolarWinds Orion API authentication bypass allows remote command executionThe SolarWinds Orion Platform API contains an authentication bypass (CWE-288/CWE-306) that lets a remote, unauthenticated attacker execute API comman…KEVEPSS 92%analysed9.8CVE-2021-27258Solarwinds orion platform improper access control vulnerabilityThis vulnerability allows remote attackers to execute escalate privileges on affected installations of SolarWinds Orion Platform 2020.2. Authenticati…EPSS 4.0%9.8CVE-2021-25274Solarwinds orion platform deserialization of untrusted data vulnerabilityThe Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set permissions on its private que…EPSS 36%9.8CVE-2019-9546Solarwinds orion platform uncontrolled search path element vulnerabilitySolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation through the RabbitMQ service.EPSS 2.8%9.6CVE-2021-35222Solarwinds orion platform cross-site scripting vulnerabilityThis vulnerability allows attackers to impersonate users and perform arbitrary actions leading to a Remote Code Execution (RCE) from the Alerts Setti…EPSS 2.6%9.0CVE-2020-13169Solarwinds orion platform cross-site scripting vulnerabilityStored XSS (Cross-Site Scripting) exists in the SolarWinds Orion Platform before before 2020.2.1 on multiple forms and pages. This vulnerability may …EPSS 2.2%8.8CVE-2022-36960Solarwinds orion platform improper input validation vulnerabilitySolarWinds Platform was susceptible to Improper Input Validation. This vulnerability allows a remote adversary with valid access to SolarWinds Web Co…EPSS 0.91%8.8CVE-2022-36964Solarwinds orion platform deserialization of untrusted data vulnerabilitySolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with valid access to Solar…EPSS 17%

Source: NIST National Vulnerability Database (record CVE-2022-36958), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.