Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-26398


SolarWinds Database Performance Analyzer was found to contain a hard-coded cryptographic key. If exploited, this vulnerability could lead to a machine-in-the-middle (MITM) attack against users. This vulnerability requires additional software not installed by default, local access to the server and administrator level privileges on the host.


Published

2025-08-12T08:15:26.193

Last Modified

2025-11-17T16:10:05.080

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.6 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-798

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application solarwinds database_performance_analyzer < 2025.3 Yes

References