Skip to content
Threat Feed
high advisory

Unauthenticated Remote Code Execution in SolarWinds Observability Self-Hosted

SolarWinds Observability Self-Hosted is vulnerable to unauthenticated remote code execution via insecure deserialization, allowing remote attackers to execute arbitrary code.

CVE search metadata

CVE search record: CVE-2026-28325. Severity: high. CVSS: 8.8. KEV: no. Product: SolarWinds Observability Self-Hosted. Brief: Unauthenticated Remote Code Execution in SolarWinds Observability Self-Hosted. Brief link: https://feed.craftedsignal.io/briefs/2026-09-solarwinds-rce/

SolarWinds Observability Self-Hosted contains an unauthenticated remote code execution (RCE) vulnerability identified as CVE-2026-28325. The flaw originates from the insecure deserialization of untrusted data processed by the application when it is configured to operate in a specific communication mode. This vulnerability allows an unauthenticated remote attacker to send specially crafted data to the application, which is then deserialized without adequate validation, leading to the execution of arbitrary code with the privileges of the application process. Given that SolarWinds observability components often run with elevated service accounts on critical infrastructure, successful exploitation could lead to full system compromise. Organizations running self-hosted instances should verify their current configuration against the vulnerability requirements provided by SolarWinds and prioritize patching or disabling the vulnerable communication mode until updates are applied.

Impact

Successful exploitation of CVE-2026-28325 allows a remote, unauthenticated attacker to execute arbitrary code on the underlying host, potentially leading to unauthorized data access, lateral movement within the network, and full compromise of the affected server.

Recommendation

  • Identify all SolarWinds Observability Self-Hosted instances in the environment.
  • Review SolarWinds security advisories to determine if your specific configuration utilizes the vulnerable communication mode.
  • Apply patches provided by SolarWinds immediately upon release to remediate CVE-2026-28325.
  • Monitor web server and application logs for anomalous POST requests to internal API endpoints that may signify attempts to inject serialized objects.

Immediate actions

Inventory all SolarWinds Observability Self-Hosted instances

IT Operations 24h

Mitigations

Patch SolarWinds Observability Self-Hosted to the version addressing CVE-2026-28325

immediate IT Operations

CVE-2026-28325