Database Management

Why SolarWinds Database Performance Analyzer (DPA) is not affected by CVE-2026-59084

This article explains why SolarWinds Database Performance Analyzer (DPA) is not affected by CVE-2026-59084.

First published date

8/3/2026 5:23 PM

Last published date

8/3/2026 5:23 PM

Overview

In 2026, the National Institute of Standards and Technology (NIST) published a security bulletin about CVE-2026-59084.

NVD - CVE-2026-59084

Product section

Database Performance Analyzer

Cause

CVE-2026-59084 is an insufficient technical documentation vulnerability in Apache Tomcat. The requirements to securely configure the EncryptInterceptor were not clearly documented.

Resolution

Solarwinds Database Performance Analyzer (DPA) is not affected by this vulnerability because it does not use the Tomcat clustering with EncryptInterceptor. The vulnerable component is not enabled or configured in the application.