← Vulnerability feed

Vulnerability record · CVE-2024-45710 · published 16 October 2024

CVE-2024-45710: Solarwinds platform uncontrolled search path element vulnerability

Solarwinds · Solarwinds Platform

SolarWinds Platform is susceptible to an Uncontrolled Search Path Element Local Privilege Escalation vulnerability. This requires a low privilege account and local access to the affected node machine.

7.8 CVSS 3.1 High EPSS 0.28% · top 81.9% CWE-427 · Uncontrolled search path element
7.8CVSS 3.1 base score
0.28%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

SolarWinds Platform is susceptible to an Uncontrolled Search Path Element Local Privilege Escalation vulnerability. This requires a low privilege account and local access to the affected node machine.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-45710 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-52606Solarwinds platform server-side request forgery (ssrf) vulnerabilitySolarWinds Platform is affected by server-side request forgery vulnerability. Proper input sanitation was not applied allowing for the possibility of…EPSS 2.5%8.8CVE-2023-40056Solarwinds platform sql injection vulnerabilitySQL Injection Remote Code Vulnerability was found in the SolarWinds Platform. This vulnerability can be exploited with a low privileged account.EPSS 4.8%8.8CVE-2023-40061Solarwinds platform improper input validation vulnerability Insecure job execution mechanism vulnerability. This vulnerability can lead to other attacks as a result.EPSS 0.42%8.8CVE-2023-40062Solarwinds platform improper input validation vulnerabilitySolarWinds Platform Incomplete List of Disallowed Inputs Remote Code Execution Vulnerability. If executed, this vulnerability would allow a low-privi…EPSS 2.7%8.0CVE-2023-35188Solarwinds platform sql injection vulnerabilitySQL Injection Remote Code Execution Vulnerability was found using a create statement in the SolarWinds Platform. This vulnerability requires user aut…EPSS 1.5%8.0CVE-2023-50395Solarwinds platform sql injection vulnerabilitySQL Injection Remote Code Execution Vulnerability was found using an update statement in the SolarWinds Platform. This vulnerability requires user au…EPSS 1.6%7.5CVE-2024-28999Solarwinds platform race condition vulnerabilityThe SolarWinds Platform was determined to be affected by a Race Condition Vulnerability affecting the web console.EPSS 14%7.5CVE-2024-28996Solarwinds platform sql injection vulnerabilityThe SolarWinds Platform was determined to be affected by a SWQL Injection Vulnerability. Attack complexity is high for this vulnerability.  EPSS 0.35%

Source: NIST National Vulnerability Database (record CVE-2024-45710), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.