VYPR
Medium severity4.8NVD Advisory· Published Jun 9, 2026· Updated Jun 9, 2026

CVE-2026-28301

CVE-2026-28301

Description

A vulnerability in SolarWinds Platform allows an attacker to craft a URL that redirects users to an unintended website, potentially leading to phishing attacks.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A vulnerability in SolarWinds Platform allows an attacker to craft a URL that redirects users to an unintended website, potentially leading to phishing attacks.

Vulnerability

A vulnerability exists in the SolarWinds Platform where a crafted external URL can redirect a user to an unintended website. The specific conditions or configurations required for this vulnerability to be triggered are not detailed in the available references. Affected versions are not explicitly mentioned.

Exploitation

An attacker could provide a specially crafted external URL to a user. If the user clicks on this URL, they may be redirected to a website controlled by the attacker, potentially for phishing purposes. No specific authentication or user interaction details beyond clicking a link are provided in the references.

Impact

Successful exploitation of this vulnerability could lead to a user being redirected to an unintended website. This could facilitate phishing attacks, where users might be tricked into revealing sensitive information or performing malicious actions on a fraudulent site. The scope of impact is limited to users who interact with the crafted URL.

Mitigation

Reference [1] lists release notes for SolarWinds Observability Self-Hosted 2026.2, which may contain fixes for various issues, but does not explicitly mention this vulnerability. Reference [2] provides general security best practices for the SolarWinds Platform, recommending the installation of the latest versions and hotfixes. Reference [3] is a security advisory page that does not provide specific mitigation details. No fixed version or explicit workaround is disclosed in the available references.

AI Insight generated on Jun 9, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

3

News mentions

0

No linked articles in our index yet.