SolarWinds Observability Self-Hosted XSS Vulnerability (CVE-2025-26391)

Summary

SolarWinds Observability Self-Hosted XSS Vulnerability. The SolarWinds Platform was susceptible to a XSS vulnerability that affects user-created URL fields. This vulnerability requires authentication from a low-level account.

Affected Products

SolarWinds Observability Self-Hosted 2025.4 and prior versions

Fixed Software Release

SolarWinds Observability Self-Hosted 2025.4 SR1

Acknowledgments

the KPN REDteam

Advisory Details
Severity
Medium
Advisory ID
First Published
11/18/2025
Last Published
11/18/2025
Fixed Version
CVSS Score
Download PDF
Send an Email