CVE-2026-28298Disclosure(solarwinds / observability_self-hosted)

LOWCVSS 8.1 · HIGH

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Patch solarwinds observability_self-hosted systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unintended script execution.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • observability_self-hosted

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 5 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-05-14)
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
observability_self-hosted

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-03-26: 1Mentions · 2026-03-29: 1Mentions · 2026-05-14: 3PoC Mentioned / Linked · 2026-05-14: 2Patch / Workaround · 2026-05-14: 1Technical Details · 2026-03-26: 1Technical Details · 2026-03-29: 1Technical Details · 2026-05-14: 203-2603-2905-14
Signal classification1 categories
Disclosure
5100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-261
Disclosure1
2026-03-291
Disclosure1
2026-05-143
Disclosure3
Full discourse5 posts
  • Andrew Oliveau@AndrewOliveau
    Disclosure

    Our team at Armadin had some fun poking at SolarWinds ☀️🌪️ Check out our latest blog: CVE-2026-28297 and CVE-2026-28298, Plus Credential Relaying for Full Domain Compromise https://www.armadin.com/blog-posts/passback-perfection-cve-2026-28297-and-cve-2026-28298-plus-credential-relaying-for-full-domain-compromise

    Post summary

    Armadin’s brief post introduces two new SolarWinds CVEs—CVE‑2026‑28297 and CVE‑2026‑28298—and credential relaying, but it does not detail the vulnerability type, PoC, or exploitation activity.

    0501641.8K
    3.3K followersView on X
  • jdelta@jdelta11
    Disclosure

    Did some research with the Armadin team on SolarWinds Observability - TL;DR two stored XSS vulnerabilities, and several passback and relay attacks. Check it out: https://www.armadin.com/blog-posts/passback-perfection-cve-2026-28297-and-cve-2026-28298-plus-credential-relaying-for-full-domain-compromise

    Post summary

    The tweet announces the discovery of two stored XSS vulnerabilities (CVE-2026-28297 and CVE-2026-28298) in SolarWinds Observability, references a detailed blog post, but does not mention patches, active exploitation, or a false positive.

    0311031.3K
    688 followersView on X
  • Armadin@ArmadinSecurity
    Disclosure

    Armadin found 2 stored XSS vulns (CVE-2026-28297/28298) in SolarWinds Observability + credential passback attacks that can lead to full domain compromise via MSSQL/LDAP relay. Fixed in Self-Hosted 2026.1.1. Full research: https://www.armadin.com/blog-posts/passback-perfection-cve-2026-28297-and-cve-2026-28298-plus-credential-relaying-for-full-domain-compromise

    Post summary

    Armadin disclosed two stored‑XSS vulnerabilities in SolarWinds Observability (CVE‑2026‑28297/28298), highlighting credential passback attacks that could lead to full domain compromise, and noted the issue is fixed in the 2026.1.1 self‑hosted release.

    00020245
    444 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28298 SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unintended script exec… https://www.cve.org/CVERecord?id=CVE-2026-28298

    Post summary

    The post announces a stored XSS flaw (CVE‑2026‑28298) in SolarWinds Observability Self‑Hosted that may allow unintended script execution, but offers no PoC, exploit, or mitigation details.

    00010166
    56.9K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    ⚡ CVE-2026-28298: SolarWinds Observability Self-Ho... Adjacent network + high privs = admin-level stored XSS in SolarWinds Observability - perfect for persistence in comprom... https://zerodaysignal.com/vulnerability/CVE-2026-28298 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    SolarWinds Observability CVE‑2026‑28298 is a stored XSS issue that could enable persistence; the post announces the vulnerability and notes the technical flaw but offers no PoC, exploit, or patch details.

    0000058
    169 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsolarwindsobservability_self-hosted---

Explore more