Vulnerability record · CVE-2023-23836 · published 15 February 2023
CVE-2023-23836: SolarWinds Platform deserialization flaw allows admin remote code execution
Solarwinds · Orion Platform
SolarWinds Platform 2022.4.1 deserializes untrusted data in the Web Console, allowing an attacker with Orion admin-level access to run arbitrary commands. The flaw is a CWE-502 issue rated CVSS 7.2 (HIGH). It matters because it turns a privileged console account into remote code execution on the server.
Description
SolarWinds Platform version 2022.4.1 was found to be susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to the SolarWinds Web Console to execute arbitrary commands.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityRequires admin privileges but yields remote code execution on a critical monitoring platform, and the very high EPSS score signals elevated exploitation likelihood.
What it is
SolarWinds Platform 2022.4.1 deserializes untrusted data in the Web Console, allowing an attacker with Orion admin-level access to run arbitrary commands. The flaw is a CWE-502 issue rated CVSS 7.2 (HIGH). It matters because it turns a privileged console account into remote code execution on the server.
Impact
An attacker with Orion admin access can execute arbitrary commands on the SolarWinds Platform host, leading to full compromise of the monitoring server and any data or credentials it holds.
Attack surface
Reachable over the network through the SolarWinds Web Console (AV:N, AC:L, UI:N), but it requires a valid Orion admin-level account (PR:H). No user interaction is needed beyond authenticated access.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented, but EPSS is very high (0.803, 99.6th percentile), indicating elevated likelihood of exploitation activity. References are limited to vendor advisory and release notes, with no public exploit details in the record.
What to do
- Upgrade SolarWinds Platform to 2023.1 or later per the vendor release notes.
- Restrict and audit Orion admin-level accounts; enforce least privilege and remove unused admin access.
- Limit network exposure of the SolarWinds Web Console to trusted management networks.
- Monitor and alert on unexpected process execution or command activity originating from the SolarWinds Platform server.
Detection
- Alert on child processes spawned by SolarWinds Platform web or service processes (e.g., w3wp.exe, SolarWinds services) that are unusual for normal operation.
- Audit Orion admin account logins and console actions for anomalous timing, source IPs, or new accounts.
- Monitor for deserialization-related errors or unusual HTTP requests to Web Console endpoints in SolarWinds logs.
- Track outbound connections from the SolarWinds server to unexpected destinations that could indicate post-exploitation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-23836 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-23836), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.