CVE-2026-28324

9.8

SolarWinds · Observability Self-Hosted

SolarWinds Observability Self-Hosted contains an unauthenticated remote code execution vulnerability caused by insufficient integrity checks in specific configurations.

Executive summary

An unauthenticated remote code execution vulnerability in SolarWinds Observability Self-Hosted poses a critical risk of full system compromise for installations using non-default configurations.

Vulnerability

The flaw stems from insufficient verification of data authenticity (CWE-345), allowing an unauthenticated remote attacker to execute arbitrary code. The vulnerability specifically impacts instances deployed in non-default and non-secure configurations.

Business impact

The potential for remote code execution allows an attacker to gain full control over the host system, leading to complete data exfiltration, service disruption, and lateral movement within the network. With a CVSS score of 9.8, this vulnerability represents the highest level of risk, as it requires no user interaction or authentication to trigger.

Remediation

Immediate Action: Upgrade to SolarWinds Observability Self-Hosted version 2026.2.3 immediately to apply the necessary integrity check patches.

Proactive Monitoring: Review system access logs for anomalous behavior and monitor for unauthorized process execution or unexpected network connections originating from the Observability platform.

Compensating Controls: Ensure the instance is configured according to the vendor security hardening guidelines and consider implementing a Web Application Firewall to filter malicious traffic targeting the platform.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical severity of this remote code execution flaw and the ease of exploitation, immediate remediation is required. Administrators should verify their current version and deployment configuration against the vendor security advisory, prioritizing the upgrade to version 2026.2.3 to eliminate the risk of unauthorized system access.

More SolarWinds CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources

Originally found and disclosed by Kai Huang from Armadin, per the CVE Program record.