← Back to CVE List
Vulnerability Intelligence Report
SolarWinds Observability Self-Hosted Remote Code Execution Vulnerability

CVE-2026-28324

SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks. Installations configured in a non-default and non-secure configuration are affected.

No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-345 ↗CWE-345 Insufficient Verification of Data Authenticity

Affected Products & Versions

Vendor Product Affected Versions
SolarWinds Observability Self-Hosted 0 < 2026.2.3 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

Identity & Timeline

StatusPUBLISHED
Assigning AuthoritySolarWinds · Vendor · USA
Reserved2026-02-26T14:46:41
Published2026-09-22T19:11:33
Last Updated2026-09-22T19:35:38

LINK COPIED TO CLIPBOARD