CVE-2026-28297Disclosure(solarwinds / observability_self-hosted)

LOWCVSS 8.7 · HIGH

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Patch solarwinds observability_self-hosted systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unintended script execution.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • observability_self-hosted

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 5 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-05-14)
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
observability_self-hosted

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-03-26: 1Mentions · 2026-03-29: 1Mentions · 2026-05-14: 3PoC Mentioned / Linked · 2026-05-14: 2Patch / Workaround · 2026-05-14: 1Technical Details · 2026-03-26: 1Technical Details · 2026-03-29: 1Technical Details · 2026-05-14: 203-2603-2905-14
Signal classification1 categories
Disclosure
5100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-261
Disclosure1
2026-03-291
Disclosure1
2026-05-143
Disclosure3
Full discourse5 posts
  • Andrew Oliveau@AndrewOliveau
    Disclosure

    Our team at Armadin had some fun poking at SolarWinds ☀️🌪️ Check out our latest blog: CVE-2026-28297 and CVE-2026-28298, Plus Credential Relaying for Full Domain Compromise https://www.armadin.com/blog-posts/passback-perfection-cve-2026-28297-and-cve-2026-28298-plus-credential-relaying-for-full-domain-compromise

    Post summary

    Armadin’s blog announces two new SolarWinds CVEs and credential relaying for domain compromise, but does not provide technical details, PoC, or exploitation evidence.

    0501641.8K
    3.3K followersView on X
  • jdelta@jdelta11
    Disclosure

    Did some research with the Armadin team on SolarWinds Observability - TL;DR two stored XSS vulnerabilities, and several passback and relay attacks. Check it out: https://www.armadin.com/blog-posts/passback-perfection-cve-2026-28297-and-cve-2026-28298-plus-credential-relaying-for-full-domain-compromise

    Post summary

    Armadin’s research reveals two stored XSS CVEs (2026-28297 and 2026-28298) in SolarWinds Observability, highlighting potential passback and relay attack vectors, with details available on their blog.

    0311031.3K
    688 followersView on X
  • Armadin@ArmadinSecurity
    Disclosure

    Armadin found 2 stored XSS vulns (CVE-2026-28297/28298) in SolarWinds Observability + credential passback attacks that can lead to full domain compromise via MSSQL/LDAP relay. Fixed in Self-Hosted 2026.1.1. Full research: https://www.armadin.com/blog-posts/passback-perfection-cve-2026-28297-and-cve-2026-28298-plus-credential-relaying-for-full-domain-compromise

    Post summary

    Armadin announced two stored XSS CVEs in SolarWinds Observability, detailing credential passback risks and providing a patch (Self-Hosted 2026.1.1) along with a research link.

    00020245
    444 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28297 SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unintended script exec… https://www.cve.org/CVERecord?id=CVE-2026-28297

    Post summary

    SolarWinds Observability Self-Hosted has been identified with a stored XSS vulnerability (CVE‑2026‑28297); no PoC, exploit code, or patch details are shared, nor is there evidence of active exploitation.

    00000105
    56.9K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    ⚡ CVE-2026-28297: SolarWinds Observability Self-Ho... SolarWinds stored XSS with high-privilege access requirement limits blast radius, but persistence in monitoring infrast... https://zerodaysignal.com/vulnerability/CVE-2026-28297 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE‑2026‑28297, a stored XSS vulnerability in SolarWinds Observability that requires high‑privilege access, indicating the vulnerability’s nature and potential impact.

    0000053
    194 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsolarwindsobservability_self-hosted---

Explore more