Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
SolarWinds recommends customers to upgrade to Observability Self-Hosted version 2026.2.3 as soon as is practical.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 22 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Solarwinds
Solarwinds observability Self-hosted |
|
| Vendors & Products |
Solarwinds
Solarwinds observability Self-hosted |
Tue, 22 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 22 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability stemming from deserialization of untrusted data when the application is configured to use a specific communication mode. | |
| Title | SolarWinds Observability Self-Hosted Unauthenticated Remote Code Execution Vulnerability | |
| Weaknesses | CWE-502 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: SolarWinds
Published:
Updated: 2026-09-22T19:36:24.025Z
Reserved: 2026-02-26T14:46:41.521Z
Link: CVE-2026-28325
Updated: 2026-09-22T19:36:05.492Z
Status : Received
Published: 2026-09-22T20:17:03.430
Modified: 2026-09-22T20:17:03.430
Link: CVE-2026-28325
No data.
OpenCVE Enrichment
Updated: 2026-09-22T20:30:08Z
-
CWE-502
Deserialization of Untrusted Data