SolarWinds Observability Self-Hosted Remote Code Execution Vulnerability (CVE-2026-28324)
Summary
SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks. Installations configured in a non-default and non-secure configuration are affected.
Affected Products
SolarWinds Observability Self-Hosted 2026.2.2 and below
Fixed Software Release
SolarWinds Observability Self-Hosted 2026.2.3
Acknowledgments
Kai Huang from Armadin
Advisory Details
Severity
9.8 Critical
Advisory ID
First Published
09/22/2026
Fixed Version