Vulnerability
Published 2026-09-24
Verified 2026-09-27

SolarWinds Observability Self-Hosted CVE-2026-28324 (CVSS 9.8): unauth RCE via insufficient integrity checks — fix 2026.2.3

SolarWinds Trust Center advisory CVE-2026-28324 documents an unauthenticated remote code execution vulnerability in Observability Self-Hosted due to insufficient integrity checks. Installations configured in a non-default and non-secure configuration are affected. CVSS 3.1 9.8 CRITICAL (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Affected: Observability Self-Hosted 2026.2.2 and below. Fixed: 2026.2.3. Credit: Kai Huang (Armadin). SolarWinds makes no mention of in-the-wild exploitation. Same patch train also addresses sibling CVE-2026-28325 (separate desk card). Distinct from Access Rights Manager CVE-2026-28326 (already on desk). Primary: SolarWinds Trust Center; wire: SecurityWeek 24 Sep 2026.

Product
SolarWinds Observability Self-Hosted
Versions
Affected: 2026.2.2 and below (non-default/non-secure configs); Fixed: 2026.2.3
CVSS
(CVSS 3.1 CRITICAL, vendor)
Exploited in Australia?
unknown
Patch to
Upgrade Observability Self-Hosted to 2026.2.3; review non-default/non-secure configuration exposure; do not expose management interfaces to untrusted networks

Primary: SolarWinds Trust Center — CVE-2026-28324 Observability Self-Hosted · Vendor: SolarWinds — Observability Self-Hosted CVE-2026-28324 · CVE: CVE-2026-28324, CVE-2026-28325, CVE-2026-28326 · SecurityWeek — SolarWinds Observability Self-Hosted RCE patches (24 Sep 2026)

vulnerabilities cloud network