SolarWinds Observability Self-Hosted Unauthenticated Remote Code Execution Vulnerability (CVE-2026-28325)

Summary

SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability stemming from deserialization of untrusted data when the application is configured to use a specific communication mode.


Affected Products

SolarWinds Observability Self-Hosted 2026.2.2 and below


Fixed Software Release

SolarWinds Observability Self-Hosted 2026.2.3


Acknowledgments

Kai Huang from Armadin

Advisory Details
Severity

8.8 High

Advisory ID
First Published

09/22/2026

Fixed Version

SolarWinds Observability Self-Hosted 2026.2.3

CVSS Score
Download PDF
Send an Email