Database Management
Why SolarWinds Database Performance Analyzer (DPA) is not affected by CVE-2026-55276
This article explains why SolarWinds Database Performance Analyzer (DPA) is not affected by CVE-2026-55276.
First published date
Last published date
Overview
In 2026, the National Institute of Standards and Technology (NIST) published a security bulletin about CVE-2026-55276.
Product section
Cause
CVE-2026-55276, an always-incorrect control flow implementation vulnerability in Apache Tomcat, meant that special roles and empty authorization constraints were not included when the effective web.xml was logged.
Resolution
SolarWinds Database Performance Analyzer (DPA) is not affected by this vulnerability. CVE-2026-55276 is limited to how Apache Tomcat generates the effective web.xml and does not impact the enforcement of configured security constraints. Therefore, this will not affect the security of the application's runtime.