CVE-2021-27258

CRITICAL

SolarWinds Orion Platform 2020.2 - Privilege Escalation

Title source: llm
STIX 2.1

Description

This vulnerability allows remote attackers to execute escalate privileges on affected installations of SolarWinds Orion Platform 2020.2. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SaveUserSetting endpoint. The issue results from improper restriction of this endpoint to unprivileged users. An attacker can leverage this vulnerability to escalate privileges their privileges from Guest to Administrator. Was ZDI-CAN-11903.

References (1)

Core 1
Core References
Third Party Advisory, VDB Entry x_refsource_misc
https://www.zerodayinitiative.com/advisories/ZDI-21-192/

Scores

CVSS v3 9.8
EPSS 0.0864
EPSS Percentile 92.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-284
Status published
Products (1)
solarwinds/orion_platform 2020.2
Published Apr 14, 2021
Tracked Since Feb 18, 2026