SolarWinds Observability Self-Hosted Remote Code Execution Vulnerability (CVE-2026-28324)

Summary

SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks. Installations configured in a non-default and non-secure configuration are affected.


Affected Products

SolarWinds Observability Self-Hosted 2026.2.2 and below


Fixed Software Release

SolarWinds Observability Self-Hosted 2026.2.3


Acknowledgments

Kai Huang from Armadin

Advisory Details
Severity

9.8 Critical

Advisory ID
First Published

09/22/2026

Fixed Version
CVSS Score
Download PDF
Send an Email