CVE-2026-28324: SolarWinds Observability Self-Hosted Remote Code Execution Vulnerability
SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks. Installations configured in a non-default and non-secure configuration are affected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SolarWinds Observability Self-Hostedto a version that resolves this vulnerability.Fixed in 2026.2.3
Event History
Frequently Asked Questions
Are default deployments affected?
No. The issue affects installations configured in a non-default, non-secure configuration.
Does exploitation require authentication or user interaction?
No. The vulnerability is described as unauthenticated remote code execution, and its vector indicates no privileges or user interaction are required.
What should teams review if they cannot immediately update?
Review the deployment against SolarWinds secure-configuration guidance and identify or remediate any non-default, non-secure configuration.