XSS Vulnerability in SolarWinds Observability Platform
CVE-2025-26391
5.4MEDIUM
Key Information:
- Vendor
Solarwinds
- Vendor
- CVE Published:
- 18 November 2025
What is CVE-2025-26391?
The SolarWinds Observability Platform has a vulnerability that allows an attacker to exploit user-created URL fields through Cross-Site Scripting (XSS). This issue involves authenticated low-level accounts and can lead to unauthorized actions within the application, potentially affecting users and their data integrity.
Affected Version(s)
SolarWinds Observability Self-Hosted Windows SolarWinds Observability Self-Hosted 2025.4 and prior versions