Network Management

Why SolarWinds Observability Self-Hosted is not affected by CVE-2026-55952, CVE-2026-55950, CVE-2026-53422, CVE-2026-54891, CVE-2026-54887, CVE-2026-54886

This article explains why SolarWinds Observability Self-Hosted is not affected by CVE-2026-55952, CVE-2026-55950, CVE-2026-53422, CVE-2026-54891, CVE-2026-54887, or CVE-2026-54886.

First published date

8/11/2026 9:44 PM

Last published date

8/11/2026 9:44 PM

Overview

In 2026, the National Institute of Standards and Technology (NIST) published a security bulletin about NVD -CVE-2026-55952, NVD - CVE-2026-55950, NVD - CVE-2026-53422, NVD - CVE-2026-54891, NVD - CVE-2026-54887, and NVD - CVE-2026-54886.

Product section

Orion Platform

Cause

CVE-2026-55952 is a Denial-of-Service vulnerability in Session Tickets in Erlang/OTP. This issue affects OTP from OTP 22.2 before OTP 29.0.3, OTP 28.5.0.3 and OTP 27.3.4.14, corresponding to ssl from 9.5 before 11.7.3, 11.6.0.3 and 11.2.12.10. The vulnerability allows unauthorized certificates to be accepted as trusted intermediate CAs, potentially enabling certificate forgery and service impersonation.

CVE-2026-55950 is a Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Erlang/OTP. This issue affects OTP from OTP 25.3 before OTP 29.0.3, OTP 28.5.0.3 and OTP 27.3.4.14, corresponding to ssl from 10.9 before 11.7.3, 11.6.0.3 and 11.2.12.10. The attack is pre-authentication: the attacker only needs to send UDP datagrams containing valid ClientHello messages from the same source IP and port before the intermediate DOWN monitor message is processed by the gen_server. No credentials, no completed handshake, and no special configuration are required, and the crash can be repeated indefinitely to create a persistent denial of service for all clients of that listener. 

CVE-2026-53422 Observable Response Discrepancy vulnerability in Erlang/OTP. This issue affects OTP from OTP 17.0 before OTP 29.0.3, OTP 28.5.0.3 and OTP 27.3.4.14, corresponding to ssh from 3.0.1 before 6.0.2, 5.5.2.2 and 5.2.11.9. The vulnerability allows the creation a path-existence oracle that an attacker can use to enumerate the filesystem structure outside the configured root, including the existence of sensitive files, directories, and mount points. The vulnerability leaks only the existence of paths. No file contents, credentials, or write access are obtainable through this issue alone. The information gained may assist further attacks when combined with other vulnerabilities.

CVE-2026-54891 is a Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Erlang/OTP.  This issue affects OTP from OTP R13B03 before OTP 27.3.4.14, from OTP 28.0 before OTP 28.5.0.3, and from OTP 29.0 before OTP 29.0.3, corresponding to ssl from 3.10.7 before 11.2.12.10, from 11.3 before 11.6.0.3, and from 11.7 before 11.7.3. The vulnerability allows network-positioned attacker can send plaintext APPLICATION_DATA records to the client during the handshake. The records are buffered and, once the handshake is completed successfully, delivered to the application as if they were authenticated post-handshake data. The attacker cannot observe the client's response or steer the connection, so the impact is limited to blind injection of unauthenticated bytes.

CVE-2026-54887 a certificate validation vulnerability in Erlang/OTP. This issue affects OTP from OTP 20.0 before OTP 29.0.3, OTP 28.5.0.3 and OTP 27.3.4.14, corresponding to ssl from 8.2 before 11.7.3, 11.6.0.3 and 11.2.12.10. The vulnerability allows an attacker who can observe the plaintext ClientHello can bypass the source address verification, enabling DTLS handshake amplification with spoofed source addresses.

CVE-2026-54886 is an infinite loop vulnerability in Erlang/OTP. This issue affects OTP from OTP 17.0 before OTP 29.0.3, OTP 28.5.0.3 and OTP 27.3.4.14, corresponding to ssh from 3.0.1 before 6.0.2, 5.5.2.2 and 5.2.11.9. The vulnerability allows an authenticated SFTP user to render an SFTP channel permanently unresponsive.

Resolution

Although SolarWinds Observability Self-Hosted includes a version of Erlang containing the reported vulnerabilities, it does not make use of the vulnerable configurations required to exploit these vulnerabilities.