Network Management
Why SolarWinds Observability Self-Hosted and Access Rights Manager (ARM) are not affected by CVE-2026-42789 and CVE-2026-42790
This article explains why SolarWinds Observability Self-Hosted and Access Rights Manager (ARM) are not affected by CVE-2026-42789 and CVE-2026-42790.
First published date
Last published date
Overview
In 2026, the National Institute of Standards and Technology (NIST) published a security bulletin about NVD - CVE-2026-42789 and NVD - CVE-2026-42790
Product section
Cause
CVE-2026-42789 is a certificate chain validation vulnerability in Erlang/OTP. This issue affects Erlang/OTP versions from 17.0 up to, but not including, 26.2.5.21, 27.3.4.12, 28.5.0.1, and 29.0.1. The vulnerability allows unauthorized certificates to be accepted as trusted intermediate CAs, potentially enabling certificate forgery and service impersonation.
CVE-2026-42790 is a certificate validation vulnerability in Erlang/OTP. This issue affects Erlang/OTP versions from 19.3 up to, but not including, 26.2.5.21, 27.3.4.12, 28.5.0.1, and 29.0.1. The vulnerability allows bypassing DNS hostname validation during TLS certificate verification, potentially enabling an attacker to impersonate a trusted service.
Resolution
Although SolarWinds Observability Self-Hosted includes a version of Erlang containing the reported certificate validation issue, the vulnerable code path is not used within the product implementation, and the product is therefore unaffected by both CVE-2026-42789 and CVE-2026-42790.
Although SolarWinds Access Rights Manager (ARM) includes a version of Erlang containing the reported certificate validation issue, the required vulnerable configuration to exploit the vulnerability is not used within the product implementation, and the product is therefore unaffected by both CVE-2026-42789 and CVE-2026-42790.