SolarWinds Observability Self-Hosted Unauthenticated Remote Code Execution Vulnerability (CVE-2026-28325)
Summary
SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability stemming from deserialization of untrusted data when the application is configured to use a specific communication mode.
Affected Products
SolarWinds Observability Self-Hosted 2026.2.2 and below
Fixed Software Release
SolarWinds Observability Self-Hosted 2026.2.3
Acknowledgments
Kai Huang from Armadin
Advisory Details
Severity
8.8 High
Advisory ID
First Published
09/22/2026
Fixed Version
SolarWinds Observability Self-Hosted 2026.2.3