CVE-2025-26397

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
24/07/2025
Last modified:
12/11/2025

Description

SolarWinds Observability Self-Hosted is susceptible to Deserialization of Untrusted Data Local Privilege Escalation vulnerability. An attacker with low privileges can escalate privileges to run malicious files copied to a permission-protected folder. This vulnerability requires authentication from a low-level account and local access to the host server.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:solarwinds:observability_self-hosted:*:*:*:*:*:*:*:* 2025.2.1 (excluding)