CVE-2026-28325
8.8SolarWinds · Observability Self-Hosted
SolarWinds Observability Self-Hosted is vulnerable to unauthenticated remote code execution via the deserialization of untrusted data in specific communication configurations.
Executive summary
SolarWinds Observability Self-Hosted contains a critical unauthenticated remote code execution vulnerability that allows attackers to gain full system control.
Vulnerability
This vulnerability is caused by insecure deserialization of untrusted data (CWE-502). An unauthenticated attacker can trigger this flaw by sending malicious payloads when the application is configured to use a specific communication mode, leading to arbitrary code execution on the underlying host.
Business impact
The ability for an unauthenticated actor to execute arbitrary code poses a severe threat to business operations and data integrity. Given the CVSS score of 8.8, this vulnerability allows for full system compromise, which could lead to unauthorized access to sensitive monitoring data, lateral movement within the network, and significant operational downtime.
Remediation
Immediate Action: Upgrade to SolarWinds Observability Self-Hosted version 2026.2.3 immediately to apply the vendor-supplied security patch.
Proactive Monitoring: Review system and application logs for anomalous deserialization patterns or unexpected process execution originating from the Observability platform.
Compensating Controls: Restrict network access to the affected service to only trusted segments, as the vulnerability requires adjacent network access to reach the vulnerable communication endpoint.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability represents a high-risk security exposure that requires prompt attention. IT administrators should prioritize the deployment of version 2026.2.3 across all instances of SolarWinds Observability Self-Hosted. Failure to patch this vulnerability leaves the environment exposed to potential remote code execution by unauthorized actors.
More SolarWinds CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
Originally found and disclosed by Kai Huang from Armadin, per the CVE Program record.