Unrated severityNVD Advisory· Published Jun 10, 2025· Updated Jun 10, 2025
SolarWinds SWOSH DOM-based reflective XSS Vulnerability
CVE-2025-26395
Description
SolarWinds Observability Self-Hosted
was susceptible to a cross-site scripting (XSS) vulnerability due to an unsanitized field in the URL. The attack requires authentication using an administrator-level account and user interaction is required.
Affected products
2- SolarWinds/SolarWinds Observability Self-Hostedv5Range: 2025.1.1 and previous versions
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.