CVE-2020-12146: Silver-Peak Unity Orchestrator

High severity, CVSS 8.8. EPSS: 27.6% chance of exploitation in the next 30 days.

In Silver Peak Unity Orchestrator versions prior to 8.9.11+, 8.10.11+, or 9.0.1+, an authenticated user can access, modify, and delete restricted files on the Orchestrator server using the/debugFiles REST API.

Affected products

  • Silver-Peak Unity Orchestrator: before 8.9.11\+ (fixed in 8.9.11\+); from 8.10, before 8.10.11\+ (fixed in 8.10.11\+); from 9.0, before 9.0.1\+ (fixed in 9.0.1\+)

Published 2020-11-05. Last modified 2026-06-17.