← Vulnerability feed

Vulnerability record · CVE-2022-38111 · published 15 February 2023

CVE-2022-38111: SolarWinds Platform deserialization allows command execution

Solarwinds · Orion Platform

SolarWinds Platform (Orion Platform) is vulnerable to deserialization of untrusted data, which lets an attacker run arbitrary commands on the host. The flaw requires an Orion admin-level account on the Web Console, so it is a post-authentication escalation path rather than an unauthenticated entry point.

7.2 CVSS 3.1 High EPSS 85% · top 0.3% CWE-502 · Deserialization of untrusted data
7.2CVSS 3.1 base score
85%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityCVSS 7.2 with high confidentiality, integrity and availability impact, and a very high EPSS score, though exploitation requires admin credentials.

What it is

SolarWinds Platform (Orion Platform) is vulnerable to deserialization of untrusted data, which lets an attacker run arbitrary commands on the host. The flaw requires an Orion admin-level account on the Web Console, so it is a post-authentication escalation path rather than an unauthenticated entry point.

Impact

An attacker with Orion admin access can execute arbitrary commands on the SolarWinds server, gaining control of the monitoring host and potentially pivoting to systems it manages.

Attack surface

Reached over the network through the SolarWinds Web Console (AV:N, AC:L, PR:H, UI:N). Exploitation requires a valid Orion admin-level account; no user interaction is needed.

Exploitation

Not listed in CISA KEV and no public exploit references are provided, but EPSS is very high (0.848, ~99.7th percentile), indicating elevated predicted exploitation activity.

What to do

  • Apply the SolarWinds Platform 2023.1 release or later, which the vendor advisory and release notes address.
  • Restrict and audit Orion admin accounts; enforce least privilege and remove unused admin access.
  • Limit network exposure of the SolarWinds Web Console to trusted management networks.
  • Monitor and alert on unexpected process execution or command activity originating from the SolarWinds server.

Detection

  • Monitor SolarWinds server logs for anomalous deserialization errors or unexpected object handling.
  • Alert on child processes spawned by the SolarWinds Web Console or Orion services.
  • Track Orion admin account logins and changes, especially outside normal maintenance windows.
  • Correlate outbound connections from the SolarWinds host to unusual destinations.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-38111 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-10148SolarWinds Orion API authentication bypass allows remote command executionThe SolarWinds Orion Platform API contains an authentication bypass (CWE-288/CWE-306) that lets a remote, unauthenticated attacker execute API comman…KEVEPSS 92%analysed9.8CVE-2021-27258Solarwinds orion platform improper access control vulnerabilityThis vulnerability allows remote attackers to execute escalate privileges on affected installations of SolarWinds Orion Platform 2020.2. Authenticati…EPSS 4.0%9.8CVE-2021-25274Solarwinds orion platform deserialization of untrusted data vulnerabilityThe Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set permissions on its private que…EPSS 36%9.8CVE-2019-9546Solarwinds orion platform uncontrolled search path element vulnerabilitySolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation through the RabbitMQ service.EPSS 2.8%9.6CVE-2021-35222Solarwinds orion platform cross-site scripting vulnerabilityThis vulnerability allows attackers to impersonate users and perform arbitrary actions leading to a Remote Code Execution (RCE) from the Alerts Setti…EPSS 2.6%9.0CVE-2020-13169Solarwinds orion platform cross-site scripting vulnerabilityStored XSS (Cross-Site Scripting) exists in the SolarWinds Orion Platform before before 2020.2.1 on multiple forms and pages. This vulnerability may …EPSS 2.2%8.8CVE-2022-36960Solarwinds orion platform improper input validation vulnerabilitySolarWinds Platform was susceptible to Improper Input Validation. This vulnerability allows a remote adversary with valid access to SolarWinds Web Co…EPSS 0.91%8.8CVE-2022-36964Solarwinds orion platform deserialization of untrusted data vulnerabilitySolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with valid access to Solar…EPSS 17%

Source: NIST National Vulnerability Database (record CVE-2022-38111), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.