SolarWinds Observability Flaws Let Unauthenticated Attackers Execute Remote Code
Brief
SolarWinds released Observability Self-Hosted 2026.
- 3 to address two critical remote code execution vulnerabilities that could let unauthenticated attackers compromise affected deployments.
The flaws, tracked as CVE-2026-28324 and CVE-2026-28325, carry CVSS severity scores of 9. 8 and 8. 8, respectively, and security researcher Kai Huang of Armadin reported them.
SolarWinds said both vulnerabilities affect deployments operating under specific non-default communication or configuration conditions, making configuration reviews as important as applying the available update.
SolarWinds Observability Flaws
CVE-2026-28324 is a critical remote code execution vulnerability with a CVSS score of 9.
- According to SolarWinds, the issue stems from insufficient integrity checks in SolarWinds Observability Self-Hosted.
