Medium severity5.4NVD Advisory· Published Nov 18, 2025· Updated Jun 17, 2026
CVE-2025-26391
CVE-2025-26391
Description
SolarWinds Observability Self-Hosted XSS Vulnerability. The SolarWinds Platform was susceptible to a XSS vulnerability that affects user-created URL fields. This vulnerability requires authentication from a low-level account.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:solarwinds:observability_self-hosted:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:solarwinds:observability_self-hosted:*:*:*:*:*:*:*:*range: <2025.4.1
- (no CPE)range: SolarWinds Observability Self-Hosted 2025.4 and prior versions
Patches
Vulnerability mechanics
References
2- documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/hco_2025-4-1_release_notes.htmnvdRelease NotesVendor Advisory
- www.solarwinds.com/trust-center/security-advisories/CVE-2025-26391nvdVendor Advisory
News mentions
0No linked articles in our index yet.