#VU113364 Deserialization of Untrusted Data in Orion Platform - CVE-2025-26397
Published: July 28, 2025 / Updated: August 1, 2025
Orion Platform
SolarWinds
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to insecure input validation when processing serialized data in SolarWinds Observability component. A local user can pass specially crafted data to the application and execute arbitrary code with elevated privileges.