Database Management
Why SolarWinds Database Performance Analyzer (DPA) is at low risk for CVE-2026-49875
This article explains why SolarWinds Database Performance Analyzer (DPA) is at low risk for CVE-2026-49875.
First published date
Last published date
Overview
In 2026, the National Institute of Standards and Technology (NIST) published a security bulletin about CVE-2026-49875.
Product section
Cause
CVE-2026-49875 is an Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution.
Resolution
While SolarWinds Database Performance Analyzer (DPA) is flagged by dependency scanning tools, our analysis shows there is a significantly lower security risk. SOAP payloads are generated internally, and no user input is utilized to construct XML payloads. Network restrictions limit access to the SOAP service as DPA runs in a secure network as recommended in the DPA Secure Configuration Guide, and web services are inaccessible to unauthenticated users due to Spring security. DPA should not be deployed in a publicly accessible, internet-facing environment.
We are tracking this dependency and plan to remove or upgrade it in a future release to fully eliminate the finding.