peter bassill · operator
$ cve CVE-2021-27258 JSON

CVE-2021-27258

9.8
CRITICAL · CVSS 3.1 · EPSS 4% (pctl 90)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

This vulnerability allows remote attackers to execute escalate privileges on affected installations of SolarWinds Orion Platform 2020.2. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SaveUserSetting endpoint. The issue results from improper restriction of this endpoint to unprivileged users. An attacker can leverage this vulnerability to escalate privileges their privileges from Guest to Administrator. Was ZDI-CAN-11903.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.98% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-284
On CISA KEVno
Public exploitnone known
Published2021-04-14
Last modified2026-06-17

Affected (1)

VendorProduct
solarwindsorion platform

References

→ the Explorer  ·  watch your stack  ·  NVD