Skip to main content
Vulnerability Database/CVE-2026-28325

CVE-2026-28325: SolarWinds Observability RCE Vulnerability

CVE-2026-28325 is an unauthenticated remote code execution vulnerability in SolarWinds Observability Self-Hosted caused by unsafe deserialization. This article covers technical details, impact assessment, and mitigation strategies.

Published:

CVE-2026-28325 Overview

CVE-2026-28325 is an unauthenticated remote code execution vulnerability in SolarWinds Observability Self-Hosted. The flaw stems from insecure deserialization of untrusted data [CWE-502] when the application is configured to use a specific communication mode. An attacker on an adjacent network can send crafted serialized objects that the server deserializes without validation, leading to arbitrary code execution in the context of the application process.

Critical Impact

Unauthenticated attackers with adjacent network access can execute arbitrary code on affected SolarWinds Observability Self-Hosted instances, resulting in full compromise of confidentiality, integrity, and availability.

Affected Products

  • SolarWinds Observability Self-Hosted (versions prior to 2026.2.3)
  • Deployments configured with the vulnerable communication mode described in the SolarWinds advisory
  • On-premises SolarWinds Orion Platform-based Observability installations

Discovery Timeline

  • 2026-09-22 - CVE-2026-28325 published to the National Vulnerability Database (NVD)
  • 2026-09-23 - Last updated in NVD database

Technical Details for CVE-2026-28325

Vulnerability Analysis

The vulnerability resides in a communication mode handler within SolarWinds Observability Self-Hosted. When this mode is enabled, the service accepts serialized objects from clients and reconstructs them using an unsafe deserializer. Because the deserializer instantiates types before validating the payload, an attacker can supply a gadget chain that triggers arbitrary method calls during object construction.

Exploitation does not require authentication. The attack surface is exposed on the local network segment where the service listens, matching an adjacent network attack vector. Successful exploitation runs code with the privileges of the affected service, which typically holds broad access to monitoring data, credentials, and downstream infrastructure targets.

Because SolarWinds Observability aggregates telemetry from across an environment, a compromise provides attackers with a foothold suitable for lateral movement, credential harvesting from stored monitoring configurations, and manipulation of observability data to hide follow-on activity.

Root Cause

The root cause is deserialization of untrusted data without type filtering or integrity validation [CWE-502]. The affected communication mode reconstructs .NET objects directly from attacker-controlled input, permitting known deserialization gadget chains to execute during type instantiation.

Attack Vector

An attacker positioned on the same broadcast domain or reachable network segment as the SolarWinds Observability Self-Hosted host sends a crafted serialized payload to the vulnerable communication endpoint. The server deserializes the payload, invokes gadget-chain methods, and executes attacker-supplied commands. No user interaction or valid credentials are required. Refer to the SolarWinds Security Advisory CVE-2026-28325 for the specific communication mode and network exposure details.

Detection Methods for CVE-2026-28325

Indicators of Compromise

  • Unexpected child processes spawned by SolarWinds Observability service accounts, particularly cmd.exe, powershell.exe, or scripting hosts.
  • Outbound network connections from the Observability host to unfamiliar IPs shortly after inbound traffic on the vulnerable communication port.
  • New scheduled tasks, services, or persistence artifacts created by the SolarWinds service account.
  • Anomalous .NET assembly loads or reflection activity in the Observability process memory space.

Detection Strategies

  • Inspect network telemetry for unauthenticated serialized payloads targeting the SolarWinds communication endpoint from adjacent hosts.
  • Alert on process-lineage anomalies where SolarWinds Observability processes spawn interactive shells or living-off-the-land binaries.
  • Correlate authentication logs, file integrity monitoring, and outbound connections from the Observability host to detect post-exploitation activity.

Monitoring Recommendations

  • Enable verbose logging on the SolarWinds Observability service and forward logs to a centralized SIEM for retention and correlation.
  • Baseline normal network traffic to the Observability host and flag deviations, especially from non-management VLANs.
  • Monitor for creation of new local accounts, group membership changes, and modifications to service binaries on the host.

How to Mitigate CVE-2026-28325

Immediate Actions Required

  • Upgrade SolarWinds Observability Self-Hosted to version 2026.2.3 or later as documented in the SolarWinds Release Notes 2026.2.3.
  • Restrict network access to the Observability host so only trusted management subnets can reach service ports.
  • Audit the Observability service account for signs of misuse and rotate credentials associated with monitored systems if compromise is suspected.

Patch Information

SolarWinds addresses CVE-2026-28325 in Observability Self-Hosted release 2026.2.3. Review the SolarWinds Security Advisory CVE-2026-28325 for the definitive list of fixed builds and follow the upgrade procedure in the official release notes.

Workarounds

  • Disable the specific communication mode identified as vulnerable in the SolarWinds advisory until the patched build is deployed.
  • Enforce network segmentation and host-based firewall rules that limit adjacent-network reachability to the vulnerable port.
  • Apply the hardening recommendations from the SolarWinds Secure Configuration Guide to reduce residual exposure.
bash
# Example: restrict inbound access to the SolarWinds Observability host using Windows Firewall
# Replace <PORT> with the vulnerable communication port and <TRUSTED_SUBNET> with your management CIDR
New-NetFirewallRule -DisplayName "SolarWinds Observability - Restrict Mgmt Only" `
  -Direction Inbound -Protocol TCP -LocalPort <PORT> `
  -RemoteAddress <TRUSTED_SUBNET> -Action Allow

New-NetFirewallRule -DisplayName "SolarWinds Observability - Block Other" `
  -Direction Inbound -Protocol TCP -LocalPort <PORT> `
  -Action Block

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.