Description
A vulnerability in which an attacker can provide a crafted external URL that may redirect a user to an unintended website.
Published: 2026-06-09
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in SolarWinds Observability Self‑Hosted allows an attacker to supply a crafted external URL that the application can redirect a user to an unintended website. This flaw can be leveraged to facilitate phishing attacks or drive traffic to malicious sites, compromising user trust and potentially exposing them to further exploits. The weakness is a classic open redirect, identified as CWE‑601, and primarily impacts the confidentiality of users’ browsing context.

Affected Systems

The affected product is SolarWinds Observability Self‑Hosted. All deployments prior to the 2026.2 release are potentially impacted, as the vendor recommends upgrading to this version to eliminate the redirect issue. There are no specific sub‑versions listed in the advisory, so any earlier 2026‑series build should be considered vulnerable until the patch is applied.

Risk and Exploitability

The CVSS score of 4.8 places the flaw in the moderate range, indicating that while the impact is not catastrophic, it is still noteworthy. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog. Based on the description, it is inferred that the attack vector is remote via the web application interface, requiring an attacker to trigger the redirect condition by supplying a malicious URL within the UI. Successful exploitation would rely on the user interacting with the redirected link, making it a user‑initiated phishing risk rather than an automated zero‑day type.

Generated by OpenCVE AI on June 9, 2026 at 17:27 UTC.

Remediation

Vendor Solution

SolarWinds recommends customers upgrade to SolarWinds Observability Self-Hosted 2026.2 when possible.


OpenCVE Recommended Actions

  • Upgrade to SolarWinds Observability Self‑Hosted 2026.2 as recommended by the vendor.
  • Restrict redirect input to trusted, whitelisted origins in the application configuration to limit exposure.
  • Deploy web‑application‑firewall rules that detect and block unexpected redirect URLs originating from the Observability Self‑Hosted service.

Generated by OpenCVE AI on June 9, 2026 at 17:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 09 Jun 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Jun 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Solarwinds
Solarwinds observability Self-hosted
Vendors & Products Solarwinds
Solarwinds observability Self-hosted

Tue, 09 Jun 2026 16:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in which an attacker can provide a crafted external URL that may redirect a user to an unintended website.
Title SolarWinds Observability Self-Hosted Open Redirect Vulnerability
Weaknesses CWE-601
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Solarwinds Observability Self-hosted
cve-icon MITRE

Status: PUBLISHED

Assigner: SolarWinds

Published:

Updated: 2026-06-09T18:40:29.361Z

Reserved: 2026-02-26T14:15:09.403Z

Link: CVE-2026-28301

cve-icon Vulnrichment

Updated: 2026-06-09T17:27:20.986Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-06-09T17:17:03.287

Modified: 2026-06-09T19:38:32.463

Link: CVE-2026-28301

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-09T17:30:10Z

Weaknesses