AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2020-10148

CRITICAL · CVSS 9.8 EPSS 91.98% CISA KEV · Actively Exploited

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2020-12-29 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CISA KEV Details

Status: This CVE is listed in CISA's Known Exploited Vulnerabilities catalog.

Ransomware use: Unknown

Added to KEV: 2021-11-03

Required action: Apply updates per vendor instructions.

CVE
CVE-2020-10148
Severity
CRITICAL
CVSS
9.8
EPSS
91.98%

Original NVD Description

The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authentication and execute API commands which may result in a compromise of the SolarWinds instance. SolarWinds Orion Platform versions 2019.4 HF 5, 2020.2 with no hotfix installed, and 2020.2 HF 1 are affected.