CVE-2026-28297: SolarWinds Observability Self-Hosted Stored Cross-Site Scripting Vulnerability
SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unintended script execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28297?
CVE-2026-28297 has a high severity rating due to the potential for exploiting stored cross-site scripting vulnerabilities.
How do I fix CVE-2026-28297?
To fix CVE-2026-28297, update SolarWinds Observability Self-Hosted to the latest version provided by the vendor.
What types of attacks can be performed using CVE-2026-28297?
CVE-2026-28297 can allow attackers to execute arbitrary scripts in the context of a user's session, leading to data theft or session hijacking.
Is CVE-2026-28297 a client-side or server-side vulnerability?
CVE-2026-28297 is a client-side vulnerability as it pertains to the execution of scripts in the user's browser.
Who is affected by CVE-2026-28297?
Organizations using the vulnerable version of SolarWinds Observability Self-Hosted are at risk of exploitation from CVE-2026-28297.