SolarWinds Observability Self-Hosted Open Redirect Vulnerability
CVE-2026-28301

4.8MEDIUM

Key Information:

Vendor

Solarwinds

Vendor
CVE Published:
9 June 2026

What is CVE-2026-28301?

A vulnerability in which an attacker can provide a crafted external URL that may redirect a user to an unintended website.

Affected Version(s)

Observability Self-Hosted 2026.1 and previous versions

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.