Database Management

Why SolarWinds Database Performance Analyzer (DPA) is not affected by CVE-2026-34197

This article explains why SolarWinds Database Performance Analyzer (DPA) is not affected by CVE-2026-34197.

First published date

5/7/2026 8:18 PM

Last published date

5/7/2026 8:18 PM

Overview

In 2026, the National Institute of Standards and Technology (NIST) published a security bulletin about CVE-2026-34197.

Product section

Database Performance Analyzer

Cause

CVE-2026-34197 is an improper input validation and improper control of generation of code vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. This vulnerability requires authentication and a crafted discovery URI.

Resolution

While the component’s presence is flagged by dependency scanning tools, our analysis shows there is no associated security risk.

DPA is not affected by CVE-2026-34197, despite using a vulnerable ActiveMQ version. The attack vector, Jolokia JMX-HTTP bridge, does not exist in DPA's deployment.