SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks. Installations configured in a non-default and non-secure configuration are affected.
Configure Player Password to secure communication between WPM Player agent and Observability Self-Hosted server. Reference : https://documentation.solarwinds.com/en/success_center/wpm/content/orionwpmagaddingalocation.htm https://documentation.solarwinds.com/en/success_center/wpm/content/orionwpmagaddingalocation.htm
SolarWinds recommends customers to upgrade to Observability Self-Hosted version 2026.2.3 as soon as is practical. If unable to update immediately, apply the recommended workaround.