CVE-2020-10148Active Exploitation(solarwinds / orion_platform)

LOWCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for solarwinds orion_platform systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authentication and execute API commands which may result in a compromise of the SolarWinds instance. SolarWinds Orion Platform versions 2019.4 HF 5, 2020.2 with no hotfix installed, and 2020.2 HF 1 are affected.

3.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-05-03. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-288CWE-306

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • orion_platform

Threat summary

  • Active exploitation appears in 3 classified signals
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 3 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-01-29); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
orion_platform

3 versions affected across 1 product

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-01-29: 1Mentions · 2026-03-21: 1Mentions · 2026-06-12: 1Mentions · 2026-06-17: 1Active Exploitation · 2026-01-29: 1Active Exploitation · 2026-03-21: 1Active Exploitation · 2026-06-17: 1Technical Details · 2026-06-12: 1Technical Details · 2026-06-17: 101-2903-2106-1206-17
Signal classification2 categories
Active Exploitation
375.0%
Disclosure
125.0%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-01-291
Active Exploitation1
2026-03-211
Active Exploitation1
2026-06-121
Disclosure1
2026-06-171
Active Exploitation1
Full discourse4 posts
  • Kat@kat_katpaints
    Disclosure

    @GGZ_71 @Mz_Informashun @FreddyLA7 1) A critical vulnerability in Dominion Democracy Suite Image Cast X system, identified as CVE-2020-10148 allowed unauthorized remote access to voting machines unpatched during the 2020 election.

    Post summary

    The tweet announces CVE-2020-10148 as a critical vulnerability in Dominion Democracy Suite Image Cast X, enabling unauthorized remote access to voting machines during the 2020 election, with no evidence of exploitation, PoC, patch, or false positive claim.

    1000033
    548 followersView on X
  • David@davidsheyi
    Active Exploitation

    3/ CVE-2020-10148 is one vulnerability exploited in supply chain attacks. Attackers leverage such CVEs to bypass authentication mechanisms. #DataBreach #RiskManagement

    Post summary

    The statement identifies CVE-2020-10148 as actively exploited in supply-chain attacks to bypass authentication mechanisms.

    1000035
    555 followersView on X
  • David@davidsheyi
    Active Exploitation

    3/ CVE-2020-10148 was one of the vulnerabilities exploited in the SolarWinds breach. This shows the importance of patch management and vulnerability scanning. #CISO #RiskManagement

    Post summary

    CVE-2020-10148 was exploited in the SolarWinds breach, highlighting the necessity of patch management and vulnerability scanning.

    1000039
    557 followersView on X
  • ThreatCluster@threatcluster
    Active Exploitation

    CVE-2020-10148 in the SolarWinds Orion API allows unauthenticated remote attackers to execute API commands on Orion Platform versions 2019.4 HF5, 2020.2 and 2020.2 HF1 and has been actively exploited, Rapid7 reported. https://threatcluster.io/cluster/critical-authentication-bypass-in-solarwinds-orion-api-cve-2-03e8a682

    Post summary

    CVE-2020-10148 is a critical authentication bypass in SolarWinds Orion that allows remote execution and is actively exploited in the wild, as reported by Rapid7.

    0000052
    356 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appsolarwindsorion_platform2019.4--
Appsolarwindsorion_platform2020.2--
Appsolarwindsorion_platform2020.2.1--

Explore more