Open Redirection Vulnerability in SolarWinds Observability Self-Hosted
CVE-2025-26394
4.8MEDIUM
Key Information:
- Vendor
Solarwinds
- Vendor
- CVE Published:
- 10 June 2025
What is CVE-2025-26394?
SolarWinds Observability Self-Hosted is exposed to an open redirection flaw, where insufficient URL validation allows an attacker to redirect users to malicious websites. This vulnerability necessitates that authentication is in place, and the attack complexity remains high, enhancing the risk of phishing and other malicious activities.
Affected Version(s)
SolarWinds Observability Self-Hosted Windows 2025.1.1 and previous versions
References
CVSS V3.1
Score:
4.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
SolarWinds would like to thank Shahzin Sajid, Al Sabah Salim, and Shabeer Ali from the QatarEnergyLNG SOC team for reporting on the issue in a responsible manner.