Database Management

Why SolarWinds Database Performance Analyzer (DPA) is not affected by CVE-2026-55276

This article explains why SolarWinds Database Performance Analyzer (DPA) is not affected by CVE-2026-55276.

First published date

7/27/2026 5:57 PM

Last published date

7/27/2026 5:57 PM

Overview

In 2026, the National Institute of Standards and Technology (NIST) published a security bulletin about CVE-2026-55276.

Product section

Database Performance Analyzer

Cause

CVE-2026-55276, an always-incorrect control flow implementation vulnerability in Apache Tomcat, meant that special roles and empty authorization constraints were not included when the effective web.xml was logged.

Resolution

SolarWinds Database Performance Analyzer (DPA) is not affected by this vulnerability. CVE-2026-55276 is limited to how Apache Tomcat generates the effective web.xml and does not impact the enforcement of configured security constraints. Therefore, this will not affect the security of the application's runtime.