Vulnerability record · CVE-2022-36961 · published 30 September 2022
CVE-2022-36961: SolarWinds Orion Platform SQL injection allows privilege escalation and RCE
Solarwinds · Orion Platform
A component of SolarWinds Orion Platform is vulnerable to SQL injection. An authenticated attacker can use the flaw to escalate privileges or execute remote code, making it a serious risk for any internet- or network-exposed Orion deployment.
Description
A vulnerable component of Orion Platform was vulnerable to SQL Injection, an authenticated attacker could leverage this for privilege escalation or remote code execution.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with network reachability and high EPSS despite no KEV listing makes this a high-priority patch for exposed Orion deployments.
What it is
A component of SolarWinds Orion Platform is vulnerable to SQL injection. An authenticated attacker can use the flaw to escalate privileges or execute remote code, making it a serious risk for any internet- or network-exposed Orion deployment.
Impact
An attacker with a valid low-privileged account can escalate to higher privileges and potentially execute arbitrary code on the Orion server, compromising the monitoring platform and any credentials or managed systems it holds.
Attack surface
Reachable over the network via the vulnerable Orion component; the CVSS vector (AV:N/PR:L/UI:N) indicates a low-privileged authenticated account is required and no user interaction is needed.
Exploitation
Not listed in CISA KEV and no public exploit or ransomware use is documented in the record, but EPSS is very high (0.75174, 99.5th percentile), suggesting elevated likelihood of exploitation activity.
What to do
- Apply the SolarWinds Orion Platform 2022.3 release or later per the vendor advisory and release notes.
- Restrict network access to the Orion web interface and management ports to trusted networks only.
- Audit and minimize Orion accounts, removing unused or over-privileged users.
- Monitor Orion database and application logs for anomalous SQL activity and unexpected privilege changes.
Detection
- Review Orion application and database logs for SQL syntax errors, UNION statements, or unusual query patterns from web-facing accounts.
- Alert on privilege changes or new administrative accounts created in Orion outside change windows.
- Monitor for unexpected child processes or command execution spawned by Orion web or application services.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/solarwinds_platform_2022-3_re | Release NotesVendor Advisory |
| https://www.solarwinds.com/trust-center/security-advisories/cve-2022-36961 | Vendor Advisory |
| https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/solarwinds_platform_2022-3_re | Release NotesVendor Advisory |
| https://www.solarwinds.com/trust-center/security-advisories/cve-2022-36961 | Vendor Advisory |
Track CVE-2022-36961 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-36961), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.