Description
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root. This issue requires group administrator access. The impact is lower in Windows deployments.
Published: 2026-07-21
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SolarWinds Serv‑U has an insecure direct object reference flaw that can be used by a malicious actor to access privileged resources and potentially execute code with root privileges. The vulnerability requires the attacker to possess group administrator credentials; the impact is mitigated in Windows deployments. The weakness is a classic case of IDOR, allowing bypass of intended access controls.

Affected Systems

SolarWinds Serv‑U, versions earlier than 2026.3. The advisory does not list specific legacy versions, but the recommendation is to upgrade to Serv‑U 2026.3 to address the issue.

Risk and Exploitability

With a CVSS score of 4.7 the risk is moderate, and the EPSS score of less than 1% indicates a low probability of active exploitation today. The flaw is not part of the CISA KEV catalog. The likely attack path involves accessing the web‑based management interface and supplying a crafted resource reference that bypasses group‑level restrictions, elevating privileges to a root‑oriented state if the attacker already holds group admin rights.

Generated by OpenCVE AI on July 30, 2026 at 17:19 UTC.

Remediation

Vendor Solution

SolarWinds recommends customers upgrade to Serv-U version 2026.3 as soon as is practical.


OpenCVE Recommended Actions

  • Upgrade to SolarWinds Serv‑U 2026.3 as soon as possible
  • Restrict group administrator accounts and require multi‑factor authentication
  • Restrict access to the Serv‑U management interface to trusted network segments and monitor for anomalous privilege‑elevating activity

Generated by OpenCVE AI on July 30, 2026 at 17:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Solarwinds
Solarwinds serv-u
Vendors & Products Solarwinds
Solarwinds serv-u

Tue, 21 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Description SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root. This issue requires group administrator access. The impact is lower in Windows deployments.
Title SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Solarwinds Serv-u
cve-icon MITRE

Status: PUBLISHED

Assigner: SolarWinds

Published:

Updated: 2026-07-24T03:55:36.930Z

Reserved: 2026-02-26T14:15:09.403Z

Link: CVE-2026-28302

cve-icon Vulnrichment

Updated: 2026-07-22T18:15:13.446Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T17:30:17Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key