← Vulnerability feed

Vulnerability record · CVE-2022-38108 · published 20 October 2022

CVE-2022-38108: SolarWinds Platform deserialization of untrusted data allows command execution

Solarwinds · Orion Platform

SolarWinds Platform (Orion Platform) is vulnerable to deserialization of untrusted data (CWE-502), which lets an attacker run arbitrary commands on the host. The flaw matters because the affected component sits in the management plane, where compromise gives broad control over monitored infrastructure. The record does not list specific affected versions or fixed builds beyond the vendor advisory reference.

7.2 CVSS 3.1 High EPSS 68% · top 0.7% CWE-502 · Deserialization of untrusted data
7.2CVSS 3.1 base score
68%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
7References
17 Jun 2026Last modified by NVD

Description

SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityRemote command execution in a management platform with a very high EPSS score, tempered by the requirement for admin-level access.

What it is

SolarWinds Platform (Orion Platform) is vulnerable to deserialization of untrusted data (CWE-502), which lets an attacker run arbitrary commands on the host. The flaw matters because the affected component sits in the management plane, where compromise gives broad control over monitored infrastructure. The record does not list specific affected versions or fixed builds beyond the vendor advisory reference.

Impact

An attacker with Orion admin-level access to the SolarWinds Web Console can execute arbitrary commands on the server, leading to full control of the SolarWinds instance and any credentials or managed systems it holds.

Attack surface

Reachable remotely over the network through the SolarWinds Web Console (AV:N), but it requires a high-privileged Orion admin account (PR:H) and no user interaction (UI:N). The description does not specify the exact endpoint or payload path.

Exploitation

Not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high (0.689, 99.3rd percentile), indicating elevated likelihood of exploitation. References include a Packet Storm remote command execution write-up and a ZDI advisory, suggesting public technical detail exists.

What to do

  • Apply the fix from the SolarWinds trust center advisory for CVE-2022-38108; patch first.
  • Restrict and audit Orion admin-level accounts, enforcing least privilege and removing unused admin access.
  • Limit network exposure of the SolarWinds Web Console to trusted management networks and place it behind strict access controls.
  • Monitor and alert on administrative account creation, privilege changes, and unexpected command execution on SolarWinds hosts.
  • Rotate credentials and secrets stored or managed by the SolarWinds instance if compromise is suspected.

Detection

  • Hunt for suspicious child processes spawned by SolarWinds/IIS worker processes on Orion servers.
  • Review Web Console and Orion admin account activity for logins or actions from unusual sources or at unusual times.
  • Monitor for deserialization-related errors or anomalous requests to SolarWinds web endpoints.
  • Correlate host telemetry on SolarWinds servers with outbound connections or command execution events.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-38108 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-10148SolarWinds Orion API authentication bypass allows remote command executionThe SolarWinds Orion Platform API contains an authentication bypass (CWE-288/CWE-306) that lets a remote, unauthenticated attacker execute API comman…KEVEPSS 92%analysed9.8CVE-2021-27258Solarwinds orion platform improper access control vulnerabilityThis vulnerability allows remote attackers to execute escalate privileges on affected installations of SolarWinds Orion Platform 2020.2. Authenticati…EPSS 4.0%9.8CVE-2021-25274Solarwinds orion platform deserialization of untrusted data vulnerabilityThe Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set permissions on its private que…EPSS 36%9.8CVE-2019-9546Solarwinds orion platform uncontrolled search path element vulnerabilitySolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation through the RabbitMQ service.EPSS 2.8%9.6CVE-2021-35222Solarwinds orion platform cross-site scripting vulnerabilityThis vulnerability allows attackers to impersonate users and perform arbitrary actions leading to a Remote Code Execution (RCE) from the Alerts Setti…EPSS 2.6%9.0CVE-2020-13169Solarwinds orion platform cross-site scripting vulnerabilityStored XSS (Cross-Site Scripting) exists in the SolarWinds Orion Platform before before 2020.2.1 on multiple forms and pages. This vulnerability may …EPSS 2.2%8.8CVE-2022-36960Solarwinds orion platform improper input validation vulnerabilitySolarWinds Platform was susceptible to Improper Input Validation. This vulnerability allows a remote adversary with valid access to SolarWinds Web Co…EPSS 0.91%8.8CVE-2022-36964Solarwinds orion platform deserialization of untrusted data vulnerabilitySolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with valid access to Solar…EPSS 17%

Source: NIST National Vulnerability Database (record CVE-2022-38108), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.