CVE-2026-28325

8.8

SolarWinds · Observability Self-Hosted

SolarWinds Observability Self-Hosted is vulnerable to unauthenticated remote code execution via the deserialization of untrusted data in specific communication configurations.

Executive summary

SolarWinds Observability Self-Hosted contains a critical unauthenticated remote code execution vulnerability that allows attackers to gain full system control.

Vulnerability

This vulnerability is caused by insecure deserialization of untrusted data (CWE-502). An unauthenticated attacker can trigger this flaw by sending malicious payloads when the application is configured to use a specific communication mode, leading to arbitrary code execution on the underlying host.

Business impact

The ability for an unauthenticated actor to execute arbitrary code poses a severe threat to business operations and data integrity. Given the CVSS score of 8.8, this vulnerability allows for full system compromise, which could lead to unauthorized access to sensitive monitoring data, lateral movement within the network, and significant operational downtime.

Remediation

Immediate Action: Upgrade to SolarWinds Observability Self-Hosted version 2026.2.3 immediately to apply the vendor-supplied security patch.

Proactive Monitoring: Review system and application logs for anomalous deserialization patterns or unexpected process execution originating from the Observability platform.

Compensating Controls: Restrict network access to the affected service to only trusted segments, as the vulnerability requires adjacent network access to reach the vulnerable communication endpoint.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability represents a high-risk security exposure that requires prompt attention. IT administrators should prioritize the deployment of version 2026.2.3 across all instances of SolarWinds Observability Self-Hosted. Failure to patch this vulnerability leaves the environment exposed to potential remote code execution by unauthorized actors.

More SolarWinds CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources

Originally found and disclosed by Kai Huang from Armadin, per the CVE Program record.