• PATCH AVAILABLE

CVE-2026-28324: pre-auth remote code execution in SolarWinds Observability Self-Hosted

An unauthenticated attacker can run arbitrary code against SolarWinds Observability Self-Hosted installations, exploiting insufficient integrity checks; this is tracked as CVE-2026-28324. The vulnerability affects 2026.x releases before 2026.2.3 and applies to installations that are configured in non-default and non-secure ways. An attacker only needs network access to the product—no credentials or user interaction are required—to exploit the flaw.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.00654
CWE
CWE-345
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: this is a pre-auth remote code execution with no login required, so prioritize patching exposed systems; the vendor published a fixed release (2026.2.3).

What is CVE-2026-28324?

An unauthenticated attacker can run arbitrary code against SolarWinds Observability Self-Hosted installations, exploiting insufficient integrity checks; this is tracked as CVE-2026-28324. The vulnerability affects 2026.x releases before 2026.2.3 and applies to installations that are configured in non-default and non-secure ways. An attacker only needs network access to the product—no credentials or user interaction are required—to exploit the flaw.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of SolarWinds Observability Self-Hosted are affected?

BRANCHAFFECTEDFIXED
2026.xbefore 2026.2.32026.2.3

Is CVE-2026-28324 being exploited?

There are no public reports of exploitation as of 2026-09-30.

How to fix CVE-2026-28324

  1. Upgrade SolarWinds Observability Self-Hosted to 2026.2.3.
  2. If you cannot upgrade immediately, restrict network exposure of the product to trusted hosts and networks.
  3. Apply the vendor's configuration guidance to remove non-default, insecure settings.
  4. Monitor application logs and network traffic for unusual activity and indicators of compromise.

Frequently asked questions

Is CVE-2026-28324 being actively exploited?

There are no public reports of active exploitation of CVE-2026-28324 as of 2026-09-30.

Which SolarWinds Observability Self-Hosted versions are affected by CVE-2026-28324?

Versions on the 2026.x branch before 2026.2.3 are affected; installations with non-default, non-secure configurations are specifically at risk.

Is there a patch for CVE-2026-28324?

Yes, SolarWinds released a fixed version: 2026.2.3.

Does CVE-2026-28324 require authentication?

No, CVE-2026-28324 is an unauthenticated vulnerability and does not require valid credentials to exploit.

References