Database Management

Why SolarWinds Database Performance Analyzer (DPA) is not affected by CVE-2026-44930

This article explains why SolarWinds Database Performance Analyzer (DPA) is not affected by CVE-2026-44930.

First published date

6/25/2026 2:53 PM

Last published date

6/25/2026 2:53 PM

Overview

In 2026, the National Institute of Standards and Technology (NIST) published a security bulletin about NVD - CVE-2026-44930.

Product section

Database Performance Analyzer

Cause

CVE-2026-44930 - An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.  

Resolution

Database Performance Analyzer (DPA) is not affected by this vulnerability; it does not use CXF's XKMS Server or its LDAP Certificate Repository.