Junglewise Threat Intelligence

CVE-2026-28324: SolarWinds Observability Self-Hosted unauthenticated remote code execution

CVE-2026-28324 · Severity: critical · CVSS 9.8 · Published 2026-09-22

Technologies: SolarWinds Observability Self-Hosted. Vendors: SolarWinds.

Executive brief

SolarWinds Observability Self-Hosted is a monitoring and observability platform that provides visibility into hybrid cloud environments and infrastructure. An unauthenticated attacker can achieve remote code execution on affected systems due to insufficient integrity checks, affecting only non-default and non-secure configurations. This vulnerability allows an attacker to take complete control of the monitoring infrastructure and the systems it oversees.

Technical details

The vulnerability stems from insufficient integrity checks in SolarWinds Observability Self-Hosted, enabling unauthenticated remote code execution. The attack requires network access and specifically targets installations running in non-default, non-secure configurations. Successful exploitation grants the attacker arbitrary code execution with the privileges of the application, compromising the entire monitoring platform.

Affected products

  • SolarWinds Observability Self-Hosted <2026.2.3

Timeline

  • 2026-09-22: disclosed

References

Related threats