Executive brief
SolarWinds Observability Self-Hosted is a platform used by IT teams to monitor and manage their infrastructure and applications. A security flaw in this software could allow an attacker to trick users into visiting malicious websites by providing a specially crafted link. This could be used in phishing attempts to steal user credentials or deliver malware, potentially compromising the security of the organization's monitoring environment.
Technical details
An open redirect vulnerability (CWE-601) exists in SolarWinds Observability Self-Hosted (formerly Hybrid Cloud Observability) versions 2026.1.1 and below. The flaw allows an attacker to craft a URL that, when processed by the application, redirects the victim to an arbitrary external domain. Exploitation requires the attacker to have low-level privileges and access to the adjacent network, with high complexity involved in the attack. This vulnerability can be leveraged to conduct sophisticated phishing attacks or bypass security filters that trust the SolarWinds domain. The issue is resolved in version 2026.2.
Affected products
- SolarWinds Observability Self-Hosted 2026.1.1 and below
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory
- 2026-06-09: patched: Fixed in version 2026.2