SolarWinds disclosed a CVSS 9.8 unauthenticated remote code execution flaw in Observability Self-Hosted, caused by insufficient integrity checks and affecting installations running in a non-default, non-secure configuration.
What Is It
CVE-2026-28324 is an unauthenticated remote code execution vulnerability in SolarWinds Observability Self-Hosted. Per the vendor advisory, the product "was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks." The flaw is classified as CWE-345 (Insufficient Verification of Data Authenticity). SolarWinds notes that only installations configured in a non-default and non-secure configuration are affected.
The CVE was published on 2026-09-22 by the SolarWinds PSIRT ([email protected]) and currently carries an NVD status of "Received."
Why It Matters
The vendor-assigned CVSS 3.1 base score is 9.8 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. That combination is the worst-case profile: network-reachable, low attack complexity, no privileges, no user interaction, with high impact to confidentiality, integrity, and availability. The exploitability subscore is 3.9; the maximum.
CISA's SSVC decision data for this CVE records exploitation as "none," automatable as "yes," and technical impact as "total." There is no CISA KEV entry for CVE-2026-28324 in the supplied data, so active exploitation is not confirmed at this time. The "automatable: yes" assessment means that if an exploit does emerge, it is expected to scale.
What's Vulnerable
- Vendor: SolarWinds
- Product: Observability Self-Hosted
- Affected versions: all versions below 2026.2.3
- Default status: unaffected; only non-default, non-secure configurations are in scope
No CPE entries were published with the NVD record.
Patch Status
Fixed in SolarWinds Observability Self-Hosted 2026.2.3. Administrators should upgrade to 2026.2.3 or later. Because exposure depends on configuration, operators should also review the SolarWinds secure configuration guidance and confirm their deployment is not running in the insecure configuration described by the advisory. No CISA KEV remediation deadline applies, as the CVE is not KEV-listed in the supplied data.
Sources
- NVD, CVE-2026-28324 (CVSS 3.1 score and vector, exploitability subscore, CWE-345 classification, affected version range, and NVD record status)
- SolarWinds Trust Center; Security Advisory CVE-2026-28324
- SolarWinds; Hybrid Cloud Observability 2026.2.3 Release Notes
- SolarWinds; Orion Platform Secure Configuration
Two things I couldn't resolve silently, flagged outside the body:
- Conflict: the editorial note says to remove the WPM link; the constraints say to keep every existing source URL. I followed the note (specific and reasoned) over the general constraint, so the WPM URL is gone. Say the word and I'll put it back.
- Truncated note: the second instruction cuts off at "and the secure-configuration lin"; I left that link and the Patch Status mention of it untouched. Send me the rest and I'll apply it.