SolarWinds Observability Self-Hosted XSS Vulnerability. The SolarWinds Platform was susceptible to a XSS vulnerability that affects user-created URL fields. This vulnerability requires authentication from a low-level account.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
SolarWinds recommends that customers upgrade to SolarWinds Observability Self-Hosted 2025.4 SR1
Workaround
No workaround given by the vendor.
References
History
Tue, 18 Nov 2025 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SolarWinds Observability Self-Hosted XSS Vulnerability. The SolarWinds Platform was susceptible to a XSS vulnerability that affects user-created URL fields. This vulnerability requires authentication from a low-level account. | |
| Title | SolarWinds Observability Self-Hosted XSS Vulnerability | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: SolarWinds
Published:
Updated: 2025-11-18T08:53:01.036Z
Reserved: 2025-02-08T00:19:09.394Z
Link: CVE-2025-26391
No data.
Status : Received
Published: 2025-11-18T09:15:50.220
Modified: 2025-11-18T09:15:50.220
Link: CVE-2025-26391
No data.
OpenCVE Enrichment
No data.