CVE-2025-26397
7.8SolarWinds · Observability Self-Hosted
SolarWinds Observability Self-Hosted contains a deserialization of untrusted data vulnerability that allows authenticated local users to escalate privileges to execute malicious files.
Executive summary
A high-severity local privilege escalation vulnerability in SolarWinds Observability Self-Hosted allows authenticated attackers with low-level access to compromise host server integrity.
Vulnerability
The software is prone to a deserialization of untrusted data flaw (CWE-502). An attacker with low-level authenticated access to the local host can manipulate deserialized objects to gain elevated privileges and execute arbitrary files.
Business impact
Successful exploitation grants an attacker administrative or system-level control over the host server, leading to potential data exfiltration, service disruption, or further lateral movement within the network. With a CVSS score of 7.8, this vulnerability represents a significant risk to the confidentiality, integrity, and availability of the affected infrastructure.
Remediation
Immediate Action: Upgrade to SolarWinds Observability Self-Hosted version 2025.2.1 or later as specified in the vendor security advisory.
Proactive Monitoring: Monitor system logs for unauthorized file modifications or unexpected process execution patterns originating from low-privilege service accounts.
Compensating Controls: Restrict local system access to authorized personnel only and enforce the principle of least privilege to minimize the potential for an attacker to reach the vulnerable entry point.
Exploitation status
Public Exploit Available: No (exploit_available unknown).
Analyst recommendation
Given the potential for full system compromise, organizations should prioritize the deployment of the 2025.2.1 patch. Administrators must verify the integrity of their host environments and ensure that access controls are strictly enforced to prevent unauthorized local account usage.
More SolarWinds CVEs
Sources
Originally found and disclosed by ccc working with the Trend Micro Zero Day Initiative, per the CVE Program record.