Database Management

Why SolarWinds Database Performance Analyzer (DPA) is at low risk for CVE-2026-49875

This article explains why SolarWinds Database Performance Analyzer (DPA) is at low risk for CVE-2026-49875.

First published date

8/10/2026 5:36 PM

Last published date

8/10/2026 5:36 PM

Overview

In 2026, the National Institute of Standards and Technology (NIST) published a security bulletin about CVE-2026-49875.

NVD - CVE-2026-49875

Product section

Database Performance Analyzer

Cause

CVE-2026-49875 is an Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution.

Resolution

While SolarWinds Database Performance Analyzer (DPA) is flagged by dependency scanning tools, our analysis shows there is a significantly lower security risk. SOAP payloads are generated internally, and no user input is utilized to construct XML payloads. Network restrictions limit access to the SOAP service as DPA runs in a secure network as recommended in the DPA Secure Configuration Guide, and web services are inaccessible to unauthenticated users due to Spring security. DPA should not be deployed in a publicly accessible, internet-facing environment.

We are tracking this dependency and plan to remove or upgrade it in a future release to fully eliminate the finding.