Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
SolarWinds recommends customers to upgrade to Observability Self-Hosted version 2026.2.3 as soon as is practical. If unable to update immediately, apply the recommended workaround.
Vendor Workaround
Configure Player Password to secure communication between WPM Player agent and Observability Self-Hosted server. Reference : https://documentation.solarwinds.com/en/success_center/wpm/content/orionwpmagaddingalocation.htm https://documentation.solarwinds.com/en/success_center/wpm/content/orionwpmagaddingalocation.htm
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 22 Sep 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Solarwinds
Solarwinds observability Self-hosted |
|
| Vendors & Products |
Solarwinds
Solarwinds observability Self-hosted |
Tue, 22 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 22 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks. Installations configured in a non-default and non-secure configuration are affected. | |
| Title | SolarWinds Observability Self-Hosted Remote Code Execution Vulnerability | |
| Weaknesses | CWE-345 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: SolarWinds
Published:
Updated: 2026-09-22T19:35:38.810Z
Reserved: 2026-02-26T14:46:41.521Z
Link: CVE-2026-28324
Updated: 2026-09-22T19:35:36.252Z
Status : Received
Published: 2026-09-22T20:17:03.250
Modified: 2026-09-22T20:17:03.250
Link: CVE-2026-28324
No data.
OpenCVE Enrichment
Updated: 2026-09-22T21:00:13Z
