Remote Code Execution Vulnerability in SolarWinds Observability Self-Hosted
CVE-2026-28325

8.8HIGH

Key Information:

Vendor

Solarwinds

Vendor
CVE Published:
22 September 2026

What is CVE-2026-28325?

The SolarWinds Observability Self-Hosted product is subjected to an unauthenticated remote code execution vulnerability. This critical flaw arises from the deserialization of untrusted data when the application operates in a particular communication mode. Attackers could exploit this vulnerability to execute arbitrary code on the affected system, making it imperative for users to apply necessary patches and secure configuration practices to mitigate potential breaches.

Affected Version(s)

Observability Self-Hosted 0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kai Huang from Armadin
.