Open Redirection Vulnerability in SolarWinds Observability Self-Hosted
CVE-2025-40545

4.8MEDIUM

Key Information:

Vendor

Solarwinds

Vendor
CVE Published:
18 November 2025

What is CVE-2025-40545?

An open redirection vulnerability exists in SolarWinds Observability Self-Hosted, allowing attackers to manipulate unsanitized URLs. This flaw could redirect authenticated users to malicious websites, posing significant security risks. Proper input validation measures should be implemented to mitigate this risk.

Affected Version(s)

SolarWinds Observability Self-Hosted Windows SolarWinds Observability Self-Hosted 2025.4 and prior versions

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Frédéric Goossens
.
CVE-2025-40545 : Open Redirection Vulnerability in SolarWinds Observability Self-Hosted