Executive brief
SolarWinds Observability Self-Hosted is a full-stack monitoring and observability platform used by IT teams to monitor complex hybrid cloud environments. An unauthenticated attacker can execute arbitrary code remotely by sending specially crafted data to an affected instance configured with a specific communication mode. This requires no user interaction and can lead to complete system compromise and data breach.
Technical details
The vulnerability is a deserialization of untrusted data flaw that allows unauthenticated remote code execution when the application is configured to use a particular communication mode. An attacker can craft malicious serialized objects and send them over the network to trigger code execution on the target system. The attack requires no authentication and can be exploited directly by a remote attacker.
Affected products
- SolarWinds Observability Self-Hosted
Timeline
- 2026-09-22: disclosed: CVE-2026-28325 published