SolarWinds Orion Platform Reflected Client-Side Template Injection Vulnerability

Vulnerability

A reflected client-side template injection vulnerability has been identified in the SolarWinds Orion Platform version 2019.2 HF1. This vulnerability allows an attacker to inject an Angular expression that escapes the Angular sandbox, potentially leading to stored cross-site scripting (XSS) attacks.

Impact

Exploitation of this vulnerability could result in reflected client-side template injection, allowing for stored cross-site scripting vulnerabilities.

Added: May 15, 2026, 9:28 AM
Updated: May 15, 2026, 9:28 AM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
1.7
exploitability
4.6
remediation
7.7
relevance
0.0
threat
0.1
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.