Back to blog
CVE-2026-28324SolarWindsSolarWinds ObservabilitymonitoringRCECVE

SolarWinds Observability Self-Hosted CVE-2026-28324: Conditional Unauthenticated 9.8 RCE

CVE-2026-28324 (9.8): unauthenticated RCE in SolarWinds Observability Self-Hosted, limited to non-default, non-secure configurations. How to assess yours.

September 24, 20263 min read

CVE-2026-28324 affects SolarWinds Observability Self-Hosted, the monitoring platform organisations host themselves. Rated 9.8, published on September 22, 2026: remote code execution without authentication.

FieldValue
CVSS 3.19.8 (CRITICAL)
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NVD published2026-09-22
CISA KEVno (as of writing)

A Condition, and a Question to Ask Yourself

SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks. Installations configured in a non-default and non-secure configuration are affected.

The second sentence is decisive: installations in the default configuration are not affected. The flaw only triggers if the configuration was changed in a direction the vendor calls non-secure.

SolarWinds doesn't publicly specify which configuration is meant, nor what "insufficient integrity checks" covers. I won't guess. What you can do is ask yourself honestly:

  • Has the configuration changed since installation — by an integrator, to fix a connectivity issue, to make an integration work?
  • Were protections disabled to "get something working": certificate checks, access restrictions, signature checks?
  • Is there documentation of how your configuration differs from the reference one?

If the answer to the last question is "no", treat yourself as potentially affected.


Why a Monitoring Platform Is a First-Order Target

The SolarWinds name recalls 2020 and the compromise of Orion's update chain. It isn't the same product or mechanism — but the reason this category is targeted hasn't changed.

A monitoring tool holds credentials to everything it watches: SNMP accounts, WMI accounts, SSH keys, service accounts on databases and hypervisors. It's connected to every network segment. And its outbound traffic to the whole estate is expected — an attacker using it to move around creates no visible anomaly.

Compromising monitoring yields, in one go, the map of the network and the keys to open it.


Versions

NVD exposes no affected-version list or fixed version at the time of writing. Check the SolarWinds advisory for the release to install — I won't invent one.


Detection

  • Unexpected child processes of the platform's services
  • Modified files in installation directories outside updates
  • Use of monitoring credentials from a source other than the platform, or at unusual times — on the target servers' side
  • Accounts and integrations recently added in the platform

Mitigation

  1. Apply the SolarWinds update as soon as it's available for your version.
  2. Return to the reference configuration following the vendor's hardening guide: it's the direct mitigation, since the default configuration isn't affected.
  3. Don't expose the platform to the internet and restrict its interface to admin networks.
  4. Reduce monitoring account privileges to the strict minimum: a read-only SNMP account can't be used to reconfigure a device.
  5. If compromised: rotate every credential stored in the platform — that's the real scope of the incident.

Why Continuous Monitoring of Your Monitoring Matters

The tool watching the estate is rarely watched itself. Yet it's one of the most privileged, and a 9.8 CVE here hinges on a configuration drift few organisations can describe.

With cveo.tech, inventory your monitoring platforms with exact versions, and get alerted whenever a critical CVE affects them.

Every Monday

The week's critical CVEs, in your inbox

One email a week: the CVSS ≥ 9 vulnerabilities published in the last seven days, plus our latest analyses. Nothing else.

Double opt-in by email. Unsubscribe in one click, any time.

Monitor CVEs with AI

AI-powered search, CVSS scoring, asset monitoring and automatic alerts.