Network Management

Why SolarWinds Observability Self-Hosted and Access Rights Manager (ARM) are not affected by CVE-2026-42789 and CVE-2026-42790

This article explains why SolarWinds Observability Self-Hosted and Access Rights Manager (ARM) are not affected by CVE-2026-42789 and CVE-2026-42790.

First published date

7/21/2026 4:31 PM

Last published date

7/21/2026 4:31 PM

Overview

In 2026, the National Institute of Standards and Technology (NIST) published a security bulletin about NVD - CVE-2026-42789 and NVD - CVE-2026-42790

Product section

Orion Platform

Cause

CVE-2026-42789 is a certificate chain validation vulnerability in Erlang/OTP. This issue affects Erlang/OTP versions from 17.0 up to, but not including, 26.2.5.21, 27.3.4.12, 28.5.0.1, and 29.0.1. The vulnerability allows unauthorized certificates to be accepted as trusted intermediate CAs, potentially enabling certificate forgery and service impersonation.

CVE-2026-42790 is a certificate validation vulnerability in Erlang/OTP. This issue affects Erlang/OTP versions from 19.3 up to, but not including, 26.2.5.21, 27.3.4.12, 28.5.0.1, and 29.0.1. The vulnerability allows bypassing DNS hostname validation during TLS certificate verification, potentially enabling an attacker to impersonate a trusted service.

Resolution

Although SolarWinds Observability Self-Hosted includes a version of Erlang containing the reported certificate validation issue, the vulnerable code path is not used within the product implementation, and the product is therefore unaffected by both CVE-2026-42789 and CVE-2026-42790.

Although SolarWinds Access Rights Manager (ARM) includes a version of Erlang containing the reported certificate validation issue, the required vulnerable configuration to exploit the vulnerability is not used within the product implementation, and the product is therefore unaffected by both CVE-2026-42789 and CVE-2026-42790.