Junglewise Threat Intelligence

CVE-2026-28322: SolarWinds Database Performance Analyzer stored XSS

CVE-2026-28322 · Severity: medium · CVSS 5.6 · Published 2026-06-30

Vendors: SolarWinds.

Executive brief

SolarWinds Database Performance Analyzer, a tool used by IT teams to monitor and optimize database health, is affected by a security flaw that allows malicious scripts to be stored within the application. If an administrative user interacts with the compromised data, the script could execute in their browser, potentially allowing an attacker to perform unauthorized actions or access sensitive information. This vulnerability requires high-level permissions and specific network proximity to exploit, reducing the overall risk to most organizations.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in SolarWinds Database Performance Analyzer due to improper input validation (CWE-20). An attacker with high privileges (PR:H) can inject malicious scripts into the application that are subsequently executed in the context of another user's browser session, typically requiring user interaction (UI:R). The attack vector is restricted to the adjacent network (AV:A) and involves high complexity (AC:H). Successful exploitation can lead to a high impact on confidentiality and integrity. The vulnerability is addressed in version 2026.2.

Affected products

  • SolarWinds Database Performance Analyzer 2026.1 and below

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: advisory
  • 2026-06-30: patched: Fixed in version 2026.2

References