Cyber & AI intelligence
Wasteland.
Briefs indexed2842
Issues29
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-28324 2026-09-22

CVE-2026-28324: Critical Unauthenticated RCE in SolarWinds Observability Self-Hosted

"SolarWinds disclosed a CVSS 9.8 unauthenticated remote code execution flaw in Observability Self-Hosted, caused by insufficient integrity checks and affecting installations running in a non-default, non-secure…"

SolarWinds disclosed a CVSS 9.8 unauthenticated remote code execution flaw in Observability Self-Hosted, caused by insufficient integrity checks and affecting installations running in a non-default, non-secure configuration.

What Is It

CVE-2026-28324 is an unauthenticated remote code execution vulnerability in SolarWinds Observability Self-Hosted. Per the vendor advisory, the product "was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks." The flaw is classified as CWE-345 (Insufficient Verification of Data Authenticity). SolarWinds notes that only installations configured in a non-default and non-secure configuration are affected.

The CVE was published on 2026-09-22 by the SolarWinds PSIRT ([email protected]) and currently carries an NVD status of "Received."

Why It Matters

The vendor-assigned CVSS 3.1 base score is 9.8 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. That combination is the worst-case profile: network-reachable, low attack complexity, no privileges, no user interaction, with high impact to confidentiality, integrity, and availability. The exploitability subscore is 3.9; the maximum.

CISA's SSVC decision data for this CVE records exploitation as "none," automatable as "yes," and technical impact as "total." There is no CISA KEV entry for CVE-2026-28324 in the supplied data, so active exploitation is not confirmed at this time. The "automatable: yes" assessment means that if an exploit does emerge, it is expected to scale.

What's Vulnerable

No CPE entries were published with the NVD record.

Patch Status

Fixed in SolarWinds Observability Self-Hosted 2026.2.3. Administrators should upgrade to 2026.2.3 or later. Because exposure depends on configuration, operators should also review the SolarWinds secure configuration guidance and confirm their deployment is not running in the insecure configuration described by the advisory. No CISA KEV remediation deadline applies, as the CVE is not KEV-listed in the supplied data.

Sources


Two things I couldn't resolve silently, flagged outside the body:

  1. Conflict: the editorial note says to remove the WPM link; the constraints say to keep every existing source URL. I followed the note (specific and reasoned) over the general constraint, so the WPM URL is gone. Say the word and I'll put it back.
  2. Truncated note: the second instruction cuts off at "and the secure-configuration lin"; I left that link and the Patch Status mention of it untouched. Send me the rest and I'll apply it.