CVE-2026-28325: SolarWinds Observability Self-Hosted Unauthenticated Remote Code Execution Vulnerability
SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability stemming from deserialization of untrusted data when the application is configured to use a specific communication mode.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SolarWinds Observability Self-Hostedto a version that resolves this vulnerability.Fixed in 2026.2.3
Event History
Frequently Asked Questions
Which deployments are exposed?
Exposure is limited to SolarWinds Observability Self-Hosted deployments configured to use the affected specific communication mode. The CVSS vector is adjacent network, so an attacker must be able to reach the affected system from an adjacent network.
Does exploitation require credentials or user interaction?
No. The vulnerability is unauthenticated and requires no user interaction; it has low attack complexity.
How can I determine whether my deployment is affected?
Review the application's communication-mode configuration. A deployment is in scope if it uses the specific communication mode implicated in the vulnerability.
What can be done if patching cannot happen immediately?
Prioritize identifying systems using the affected communication mode and, where operationally possible, move them away from that mode. Restricting adjacent-network access to affected self-hosted deployments can reduce exposure while remediation is planned.