CVE-2025-26391: SolarWinds Observability Self-Hosted XSS Vulnerability
SolarWinds Observability Self-Hosted XSS Vulnerability. The SolarWinds Platform was susceptible to a XSS vulnerability that affects user-created URL fields. This vulnerability requires authentication from a low-level account.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26391?
CVE-2025-26391 has been classified as a medium severity vulnerability due to its exploitation potential via user-created URL fields.
How do I fix CVE-2025-26391?
To mitigate CVE-2025-26391, users should update to the latest version of SolarWinds Observability that addresses the XSS vulnerability.
Who is affected by CVE-2025-26391?
Users of SolarWinds Observability with low-level account access are particularly vulnerable to CVE-2025-26391.
What type of vulnerability is CVE-2025-26391?
CVE-2025-26391 is classified as a cross-site scripting (XSS) vulnerability.
Can CVE-2025-26391 be exploited without authentication?
No, CVE-2025-26391 requires authentication from a low-level account to be exploited.