← Vulnerability feed

Vulnerability record · CVE-2023-40061 · published 1 November 2023

CVE-2023-40061: Solarwinds platform improper input validation vulnerability

Solarwinds · Solarwinds Platform

 Insecure job execution mechanism vulnerability. This vulnerability can lead to other attacks as a result.

8.8 CVSS 3.1 High EPSS 0.42% · top 66.3% CWE-20 · Improper input validation
8.8CVSS 3.1 base score
0.42%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

 Insecure job execution mechanism vulnerability. This vulnerability can lead to other attacks as a result.

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-40061 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-52606Solarwinds platform server-side request forgery (ssrf) vulnerabilitySolarWinds Platform is affected by server-side request forgery vulnerability. Proper input sanitation was not applied allowing for the possibility of…EPSS 2.5%8.8CVE-2023-40056Solarwinds platform sql injection vulnerabilitySQL Injection Remote Code Vulnerability was found in the SolarWinds Platform. This vulnerability can be exploited with a low privileged account.EPSS 4.8%8.8CVE-2023-40062Solarwinds platform improper input validation vulnerabilitySolarWinds Platform Incomplete List of Disallowed Inputs Remote Code Execution Vulnerability. If executed, this vulnerability would allow a low-privi…EPSS 2.7%8.0CVE-2023-35188Solarwinds platform sql injection vulnerabilitySQL Injection Remote Code Execution Vulnerability was found using a create statement in the SolarWinds Platform. This vulnerability requires user aut…EPSS 1.5%8.0CVE-2023-50395Solarwinds platform sql injection vulnerabilitySQL Injection Remote Code Execution Vulnerability was found using an update statement in the SolarWinds Platform. This vulnerability requires user au…EPSS 1.6%7.8CVE-2024-45710Solarwinds platform uncontrolled search path element vulnerabilitySolarWinds Platform is susceptible to an Uncontrolled Search Path Element Local Privilege Escalation vulnerability. This requires a low privilege acc…EPSS 0.28%7.5CVE-2024-28999Solarwinds platform race condition vulnerabilityThe SolarWinds Platform was determined to be affected by a Race Condition Vulnerability affecting the web console.EPSS 14%7.5CVE-2024-28996Solarwinds platform sql injection vulnerabilityThe SolarWinds Platform was determined to be affected by a SWQL Injection Vulnerability. Attack complexity is high for this vulnerability.  EPSS 0.35%

Source: NIST National Vulnerability Database (record CVE-2023-40061), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.