← Vulnerability feed

Vulnerability record · CVE-2023-23836 · published 15 February 2023

CVE-2023-23836: SolarWinds Platform deserialization flaw allows admin remote code execution

Solarwinds · Orion Platform

SolarWinds Platform 2022.4.1 deserializes untrusted data in the Web Console, allowing an attacker with Orion admin-level access to run arbitrary commands. The flaw is a CWE-502 issue rated CVSS 7.2 (HIGH). It matters because it turns a privileged console account into remote code execution on the server.

7.2 CVSS 3.1 High EPSS 80% · top 0.4% CWE-502 · Deserialization of untrusted data
7.2CVSS 3.1 base score
80%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

SolarWinds Platform version 2022.4.1 was found to be susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to the SolarWinds Web Console to execute arbitrary commands.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityRequires admin privileges but yields remote code execution on a critical monitoring platform, and the very high EPSS score signals elevated exploitation likelihood.

What it is

SolarWinds Platform 2022.4.1 deserializes untrusted data in the Web Console, allowing an attacker with Orion admin-level access to run arbitrary commands. The flaw is a CWE-502 issue rated CVSS 7.2 (HIGH). It matters because it turns a privileged console account into remote code execution on the server.

Impact

An attacker with Orion admin access can execute arbitrary commands on the SolarWinds Platform host, leading to full compromise of the monitoring server and any data or credentials it holds.

Attack surface

Reachable over the network through the SolarWinds Web Console (AV:N, AC:L, UI:N), but it requires a valid Orion admin-level account (PR:H). No user interaction is needed beyond authenticated access.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented, but EPSS is very high (0.803, 99.6th percentile), indicating elevated likelihood of exploitation activity. References are limited to vendor advisory and release notes, with no public exploit details in the record.

What to do

  • Upgrade SolarWinds Platform to 2023.1 or later per the vendor release notes.
  • Restrict and audit Orion admin-level accounts; enforce least privilege and remove unused admin access.
  • Limit network exposure of the SolarWinds Web Console to trusted management networks.
  • Monitor and alert on unexpected process execution or command activity originating from the SolarWinds Platform server.

Detection

  • Alert on child processes spawned by SolarWinds Platform web or service processes (e.g., w3wp.exe, SolarWinds services) that are unusual for normal operation.
  • Audit Orion admin account logins and console actions for anomalous timing, source IPs, or new accounts.
  • Monitor for deserialization-related errors or unusual HTTP requests to Web Console endpoints in SolarWinds logs.
  • Track outbound connections from the SolarWinds server to unexpected destinations that could indicate post-exploitation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-23836 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-10148SolarWinds Orion API authentication bypass allows remote command executionThe SolarWinds Orion Platform API contains an authentication bypass (CWE-288/CWE-306) that lets a remote, unauthenticated attacker execute API comman…KEVEPSS 92%analysed9.8CVE-2021-27258Solarwinds orion platform improper access control vulnerabilityThis vulnerability allows remote attackers to execute escalate privileges on affected installations of SolarWinds Orion Platform 2020.2. Authenticati…EPSS 4.0%9.8CVE-2021-25274Solarwinds orion platform deserialization of untrusted data vulnerabilityThe Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set permissions on its private que…EPSS 36%9.8CVE-2019-9546Solarwinds orion platform uncontrolled search path element vulnerabilitySolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation through the RabbitMQ service.EPSS 2.8%9.6CVE-2021-35222Solarwinds orion platform cross-site scripting vulnerabilityThis vulnerability allows attackers to impersonate users and perform arbitrary actions leading to a Remote Code Execution (RCE) from the Alerts Setti…EPSS 2.6%9.0CVE-2020-13169Solarwinds orion platform cross-site scripting vulnerabilityStored XSS (Cross-Site Scripting) exists in the SolarWinds Orion Platform before before 2020.2.1 on multiple forms and pages. This vulnerability may …EPSS 2.2%8.8CVE-2022-36960Solarwinds orion platform improper input validation vulnerabilitySolarWinds Platform was susceptible to Improper Input Validation. This vulnerability allows a remote adversary with valid access to SolarWinds Web Co…EPSS 0.91%8.8CVE-2022-36964Solarwinds orion platform deserialization of untrusted data vulnerabilitySolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with valid access to Solar…EPSS 17%

Source: NIST National Vulnerability Database (record CVE-2023-23836), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.