Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-28324: SolarWinds Observability Self-Hosted can run attacker code
CVE-2026-28324 · published 18 days ago
Summary
If SolarWinds Observability Self-Hosted is set up with custom, insecure settings, someone on the network can make the server run any program they choose without logging in. This could let an attacker take control of the system or steal data. Apply the latest update from SolarWinds, switch back to the default secure configuration, and restrict network access to the server.
What to do
- Update solarwinds observability self-hosted to version 2026.2.3 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| solarwinds | observability self-hosted | < 2026.2.3 |
Original advisory text
SolarWinds Observability Self-Hosted Remote Code Execution Vulnerability
SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks. Installations configured in a non-default and non-secure configuration are affected.
References
- https://documentation.solarwinds.com/en/success_center/orionplatform/content/rel...
- https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28324
- https://documentation.solarwinds.com/en/success_center/orionplatform/content/cor...
- https://documentation.solarwinds.com/en/success_center/wpm/content/orionwpmagadd...
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-345Insufficient Verification of Data Authenticity
Timeline
Published22 Sep 2026
Updated11 Oct 2026
First seen22 Sep 2026
Track software like this
Free during beta