Database Management

Why SolarWinds Database Performance Analyzer (DPA) is not affected by CVE-2026-42498

This article explains why SolarWinds Database Performance Analyzer (DPA) is not affected by CVE-2026-42498.

First published date

6/23/2026 3:12 PM

Last published date

6/23/2026 3:12 PM

Overview

In 2026, the National Institute of Standards and Technology (NIST) published a security bulletin about CVE-2026-42498.

NVD - CVE-2026-42498

Product section

Database Performance Analyzer

Cause

CVE-2026-42498 is an exposure of HTTP authentication header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat.

Resolution

Database Performance Analyzer (DPA) does not use Tomcat WebSocket client to make outbound connections and is therefore not affected by the vulnerability.