CVE-2021-27258
9.8
CRITICAL · CVSS 3.1 · EPSS 4% (pctl 90)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
This vulnerability allows remote attackers to execute escalate privileges on affected installations of SolarWinds Orion Platform 2020.2. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SaveUserSetting endpoint. The issue results from improper restriction of this endpoint to unprivileged users. An attacker can leverage this vulnerability to escalate privileges their privileges from Guest to Administrator. Was ZDI-CAN-11903.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.98% — more likely to be exploited than 90% of all CVEs |
| Weakness | CWE-284 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2021-04-14 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| solarwinds | orion platform |
References
→ the Explorer · watch your stack · NVD