← Vulnerability feed

Vulnerability record · CVE-2022-36960 · published 29 November 2022

CVE-2022-36960: Solarwinds orion platform improper input validation vulnerability

Solarwinds · Orion Platform

SolarWinds Platform was susceptible to Improper Input Validation. This vulnerability allows a remote adversary with valid access to SolarWinds Web Console to escalate user privileges.

8.8 CVSS 3.1 High EPSS 0.91% · top 41.5% CWE-20 · Improper input validationCWE-287 · Improper authentication
8.8CVSS 3.1 base score
0.91%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

SolarWinds Platform was susceptible to Improper Input Validation. This vulnerability allows a remote adversary with valid access to SolarWinds Web Console to escalate user privileges.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-36960 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-10148SolarWinds Orion API authentication bypass allows remote command executionThe SolarWinds Orion Platform API contains an authentication bypass (CWE-288/CWE-306) that lets a remote, unauthenticated attacker execute API comman…KEVEPSS 92%analysed9.8CVE-2021-27258Solarwinds orion platform improper access control vulnerabilityThis vulnerability allows remote attackers to execute escalate privileges on affected installations of SolarWinds Orion Platform 2020.2. Authenticati…EPSS 4.0%9.8CVE-2021-25274Solarwinds orion platform deserialization of untrusted data vulnerabilityThe Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set permissions on its private que…EPSS 36%9.8CVE-2019-9546Solarwinds orion platform uncontrolled search path element vulnerabilitySolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation through the RabbitMQ service.EPSS 2.8%9.6CVE-2021-35222Solarwinds orion platform cross-site scripting vulnerabilityThis vulnerability allows attackers to impersonate users and perform arbitrary actions leading to a Remote Code Execution (RCE) from the Alerts Setti…EPSS 2.6%9.0CVE-2020-13169Solarwinds orion platform cross-site scripting vulnerabilityStored XSS (Cross-Site Scripting) exists in the SolarWinds Orion Platform before before 2020.2.1 on multiple forms and pages. This vulnerability may …EPSS 2.2%8.8CVE-2022-36964Solarwinds orion platform deserialization of untrusted data vulnerabilitySolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with valid access to Solar…EPSS 17%8.8CVE-2022-36958SolarWinds Platform Web Console deserialization allows remote command executionSolarWinds Platform (Orion Platform) deserializes untrusted data, letting an attacker run arbitrary commands. The flaw is reachable remotely through …EPSS 82%analysed

Source: NIST National Vulnerability Database (record CVE-2022-36960), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.