SolarWinds SWOSH DOM-based reflective XSS Vulnerability (CVE-2025-26395)

Summary

SolarWinds SWOSH was susceptible to a cross-site scripting (XSS) vulnerability due to an unsanitized field in the URL. The attack requires authentication using an administrator-level account and user interaction is required.

Affected Products

SolarWinds SWOSH 2025.1.1 and prior versions

Fixed Software Release

SWOSH 2025.2

Acknowledgments

Shahzin Sajid, Al Sabah Salim, and Shabeer Ali from the QatarEnergyLNG SOC team

Advisory Detail
Severity
High
Advisory ID
First Published
06/10/2025
Fixed Version
CVSS Score
Download PDF
Send an Email