← Vulnerability feed

Vulnerability record · CVE-2025-26395 · published 10 June 2025

CVE-2025-26395: Solarwinds observability self-hosted cross-site scripting vulnerability

Solarwinds · Observability Self Hosted

SolarWinds Observability Self-Hosted was susceptible to a cross-site scripting (XSS) vulnerability due to an unsanitized field in the URL. The attack requires authentication using an administrator-level account and user interaction is required.

4.3 CVSS 3.1 Medium EPSS 0.21% · top 90.3% CWE-79 · Cross-site scripting
4.3CVSS 3.1 base score
0.21%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

SolarWinds Observability Self-Hosted was susceptible to a cross-site scripting (XSS) vulnerability due to an unsanitized field in the URL. The attack requires authentication using an administrator-level account and user interaction is required.

CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-26395 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.7CVE-2026-28297Solarwinds observability self-hosted cross-site scripting vulnerabilitySolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unint…EPSS 0.45%8.1CVE-2026-28298Solarwinds observability self-hosted cross-site scripting vulnerabilitySolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unint…EPSS 0.42%7.8CVE-2025-26397Solarwinds observability self-hosted deserialization of untrusted data vulnerabilitySolarWinds Observability Self-Hosted is susceptible to Deserialization of Untrusted Data Local Privilege Escalation vulnerability. An attacker with l…EPSS 0.30%5.4CVE-2025-26391Solarwinds observability self-hosted cross-site scripting vulnerabilitySolarWinds Observability Self-Hosted XSS Vulnerability. The SolarWinds Platform was susceptible to a XSS vulnerability that affects user-created URL …EPSS 0.28%4.8CVE-2025-26394Solarwinds observability self-hosted open redirect vulnerabilitySolarWinds Observability Self-Hosted is susceptible to an open redirection vulnerability. The URL is not properly sanitized, and an attacker could ma…EPSS 0.19%4.6CVE-2025-26392Solarwinds observability self-hosted sql injection vulnerabilitySolarWinds Observability Self-Hosted is susceptible to SQL injection vulnerability that may display sensitive data using a low-level account. This vu…EPSS 0.24%4.4CVE-2025-40545Solarwinds observability self-hosted open redirect vulnerabilitySolarWinds Observability Self-Hosted is susceptible to an open redirection vulnerability. The URL is not properly sanitized, and an attacker could ma…EPSS 0.23%6.1CVE-2026-42897Microsoft Exchange Server XSS enables spoofingMicrosoft Exchange Server and Exchange Server Subscription Edition fail to neutralize input during web page generation, a cross-site scripting flaw (…KEVEPSS 0.52%analysed

Source: NIST National Vulnerability Database (record CVE-2025-26395), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.