Network Management

"Vulnerability and Risk" dashboard visible for non admin users in SolarWinds Platform 2025.2.1

The "Vulnerability and Risk" dashboard is visible in the SolarWinds Platform Web Console for non-admin users despite their lack of the necessary permissions.

First published date

8/21/2025 4:01 PM

Last published date

12/19/2025 11:07 PM

Overview

In SolarWinds Platform 2025.2.1, an issue occurs where non-admin users without explicit security roles assigned can access restricted dashboards. To replicate the issue:
  1. Create a non-admin user with the security role set to "None."
  2. Log in using that account.
  3. Attempt to access the Vulnerability and Risk Dashboard and Security Summary.
Expected Result: A 403 Forbidden message should be displayed, preventing access.
Actual Result: The dashboards are visible to the user despite lacking permissions.

Product section

Orion Platform

Cause

This has been identified as a known issue in SolarWinds Platform 2025.2.1.

Resolution

To resolve this issue, please upgrade to SolarWinds Platform 2025.4 and above. There is no known workaround.