Medium severity4.8NVD Advisory· Published Nov 18, 2025· Updated Jun 17, 2026
CVE-2025-40545
CVE-2025-40545
Description
SolarWinds Observability Self-Hosted is susceptible to an open redirection vulnerability. The URL is not properly sanitized, and an attacker could manipulate the string to redirect a user to a malicious site. The attack complexity is high, and authentication is required.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:solarwinds:observability_self-hosted:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:solarwinds:observability_self-hosted:*:*:*:*:*:*:*:*range: <2025.4.1
- (no CPE)
- (no CPE)range: SolarWinds Observability Self-Hosted 2025.4 and prior versions
Patches
Vulnerability mechanics
References
2- documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/hco_2025-4-1_release_notes.htmnvdRelease NotesVendor Advisory
- www.solarwinds.com/trust-center/security-advisories/CVE-2025-40545nvdVendor Advisory
News mentions
0No linked articles in our index yet.