CVE-2026-28325
📛 CVE Title
SolarWinds Observability Self-Hosted Unauthenticated Remote Code Execution Vulnerability
Description
SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability stemming from deserialization of untrusted data when the application is configured to use a specific communication mode.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- SolarWinds
- CVSS severity
- HIGH
- CVSS score
- 8.8 / 10
- CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Effective score
- 8.8 / 10 HIGH source: CNA overview
- CWE(s)
-
CWE-502 - Reserved
- 2026-02-26
- Published
- 2026-09-22 19:12 UTC
- Last updated
- 2026-09-22 19:36 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/28xxx/CVE-2026-28325.json
- Linked Threat
- CVE-2026-28325 — SolarWinds Observability Self-Hosted Unauthenticated Remote Code Execution Vulnerability
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-09-22 20:17:03 UTC
- NVD last modified
- 2026-09-22 20:17:03 UTC
- NVD CVSS v3.1
- 8.8 / 10 HIGH source: psirt@solarwinds.com
- NVD CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Exploitability subscore
- 2.8 / 10
- Impact subscore
- 5.9 / 10
NVD / KEV / EPSS data refreshed 2026-09-23 01:41 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-84678 - Assigner
- SolarWinds
- Published
- Sep 22, 2026, 7:12:44 PM
- Updated
- Sep 23, 2026, 3:56:15 AM
- EUVD base score (CVSS 3.1)
-
8.8 / 10
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EUVD-reported EPSS
- 0.0000
- Vendors
- SolarWinds
- Products
-
Observability Self-Hosted (0 <2026.2.3)
- Aliases
-
GHSA-r476-9mp7-phxc
ENISA description: SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability stemming from deserialization of untrusted data when the application is configured to use a specific communication mode.
EUVD references (3)
- https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/hco_2026-2-3_release_notes.htm
- https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28325
- https://documentation.solarwinds.com/en/success_center/orionplatform/content/core-secure-configuration.htm
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| SolarWinds | Observability Self-Hosted |
0 (affected)
|
— |
Vendor references (3)
References embedded in the original CVE record by the assigning CNA.
- https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/hco_2026-2-3_release_notes.htm release-notes
- https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28325 vendor-advisory
- https://documentation.solarwinds.com/en/success_center/orionplatform/content/core-secure-configuration.htm x_secure-configuration-guide
Web references (0)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
No web references attached yet.
NVD-tagged references (3)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://documentation.solarwinds.com/en/success_center/orionplatform/content/core-secure-configuration.htm psirt@solarwinds.com
- https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/hco_2026-2-3_release_notes.htm psirt@solarwinds.com
- https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28325 psirt@solarwinds.com
Remediations (10)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:0daynews.com
CVE - 2026 -28326 (CVSS 8.8) in SolarWinds Access Rights Manager through 2026.2 lets unauthenticated attackers execute code. Patch ARM 2026.2.1 is available now.
2026-09-23 15:18 UTC -
web:app.opencve.io
SolarWinds Observability Self‑Hosted installations are impacted. The vulnerability applies to any deployed version that is older than the patched release 2026.2.3 and that has the vulnerable communication mode enabled. No specific version range is provided in the CVE , so all current releases without the patch are considered at risk.
2026-09-23 15:18 UTC -
web:arcticwolf.com
Learn about critical SolarWinds Web Help Desk vulnerabilities CVE - 2026 -28323 and CVE - 2026 -28299, including patch guidance, mitigation steps, and security recommendations.
2026-09-23 15:18 UTC -
web:cvebrief.com
Remediation Immediate Action: Upgrade to SolarWinds Observability Self-Hosted version 2026.2.3 immediately to apply the vendor-supplied security patch . Proactive Monitoring: Review system and application logs for anomalous deserialization patterns or unexpected process execution originating from the Observability platform.
2026-09-23 15:18 UTC -
web:cvetodo.com
CVE-2026-28325 is an Insecure Deserialization vulnerability in Observability Self Hosted. Includes technical details, affected versions, and mitigation steps.
2026-09-23 15:18 UTC -
web:cyberpress.org
SolarWinds released Observability Self-Hosted 2026.2.3 to address two critical remote code execution vulnerabilities that could let unauthenticated attackers compromise affected deployments. The flaws, tracked as CVE - 2026 -28324 and CVE-2026-28325 , carry CVSS severity scores of 9.8 and 8.8, respectively, and security researcher Kai Huang of Armadin reported them. SolarWinds said both ...
2026-09-23 15:18 UTC -
web:support.microsoft.com
Be aware that the update in the Microsoft Download Center applies to the Microsoft Installer (.msi)-based edition of Office 2016. It doesn't apply to the Office 2016 Click-to-Run editions, such as Microsoft Office 365 Home. (See What version of Office am I using?) How to get and install the update Method 1: Microsoft Update This update is available from Microsoft Update. When you turn on ...
2026-09-23 15:18 UTC -
web:techjacksolutions.com
Executive Summary SolarWinds released Observability Self-Hosted version 2026.2.3 on September 22, 2026 , to address two unauthenticated remote code execution vulnerabilities tracked as CVE - 2026 -28324 and CVE-2026-28325 , according to the vendor advisory as reported by Cybersecurity News.
2026-09-23 15:18 UTC -
web:www.cisecurity.org
<p>Multiple vulnerabilities have been discovered in Microsoft products, the most severe of which could allow for remote code execution. Successful exploitation of the most severe of these vulnerabilities could result in an attacker gaining the same privileges as the logged-on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or ...
2026-09-23 15:18 UTC -
web:www.oracle.com
This Critical Patch Update contains 1448 new security patches across the product families listed below. Please note that a My Oracle Support (MOS) note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at July 2026 Critical Patch Update: Executive Summary and Analysis.
2026-09-23 15:18 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2026-28325.json.
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-28325",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-22T19:36:00.487002Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T19:36:24.025Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "Observability Self-Hosted",
"vendor": "SolarWinds",
"versions": [
{
"lessThan": "2026.2.3",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"user": "00000000-0000-4000-9000-000000000000",
"value": "Kai Huang from Armadin"
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "<span style=\"background-color: rgb(255, 255, 255);\">SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability stemming from deserialization of untrusted data when the application is configured to use a specific communication mode.</span><span style=\"background-color: rgb(96, 96, 96);\"> </span>"
}
],
"value": "SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability stemming from deserialization of untrusted data when the application is configured to use a specific communication mode."
}
],
"impacts": [
{
"capecId": "CAPEC-549",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-549 Local Execution of Code"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "ADJACENT_NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-502",
"description": "CWE-502 Deserialization of Untrusted Data",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T19:12:44.576Z",
"orgId": "49f11609-934d-4621-84e6-e02e032104d6",
"shortName": "SolarWinds"
},
"references": [
{
"tags": [
"release-notes"
],
"url": "https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/hco_2026-2-3_release_notes.htm"
},
{
"tags": [
"vendor-advisory"
],
"url": "https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28325"
},
{
"tags": [
"x_secure-configuration-guide"
],
"url": "https://documentation.solarwinds.com/en/success_center/orionplatform/content/core-secure-configuration.htm"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "SolarWinds recommends customers to upgrade to Observability Self-Hosted version 2026.2.3 as soon as is practical."
}
],
"value": "SolarWinds recommends customers to upgrade to Observability Self-Hosted version 2026.2.3 as soon as is practical."
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "SolarWinds Observability Self-Hosted Unauthenticated Remote Code Execution Vulnerability",
"x_generator": {
"engine": "Vulnogram 0.1.0-dev"
}
}
},
"cveMetadata": {
"assignerOrgId": "49f11609-934d-4621-84e6-e02e032104d6",
"assignerShortName": "SolarWinds",
"cveId": "CVE-2026-28325",
"datePublished": "2026-09-22T19:12:44.576Z",
"dateReserved": "2026-02-26T14:46:41.521Z",
"dateUpdated": "2026-09-22T19:36:24.025Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}