Description
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution as root. A domain account with admin privileges and read and write access to the home directory is required. The impact is lower in Windows deployments.
Published: 2026-07-21
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an insecure direct object reference that allows an attacker who can provide or alter references to internal resources to cause the Serv-U server to execute arbitrary code with root privileges. The flaw can be triggered by a domain account that has administrative rights and read/write permission on its home directory, thereby giving the attacker the capability to run native system commands. While the description indicates that the impact is mitigated in Windows deployments, the potential for full system compromise remains in affected environments.

Affected Systems

SolarWinds Serv-U services are vulnerable. No specific version range was enumerated, but the vendor's recommendation is to upgrade to Serv-U 2026.3 once possible. All other earlier Serv-U releases that have not been patched remain at risk.

Risk and Exploitability

The CVSS score of 4.7 suggests a moderate severity, but the EPSS score of less than 1% implies that the probability of exploitation is low at present. The case is not listed in the CISA KEV catalog, which further indicates that no widespread exploit has been documented. Nonetheless, the attack vector requires privileged domain credentials and write access to the user's home directory; therefore, exploitation is best considered an insider threat or a targeted breach in which an attacker has already compromised a privileged account. Effective mitigation will rely on disabling or limiting those privileged rights and applying the vendor's patch.

Generated by OpenCVE AI on July 30, 2026 at 17:19 UTC.

Remediation

Vendor Solution

SolarWinds recommends customers to upgrade to Serv-U version 2026.3 as soon as is practical.


OpenCVE Recommended Actions

  • Upgrade Serv-U to version 2026.3 to apply the vendor's fix.
  • Restrict domain accounts with administrator privileges so that only those that truly need access have write rights to home directories.
  • Audit and adjust file system permissions to ensure that user home directories are not writable by accounts lacking legitimate operational necessity.

Generated by OpenCVE AI on July 30, 2026 at 17:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Solarwinds
Solarwinds serv-u
Vendors & Products Solarwinds
Solarwinds serv-u

Tue, 21 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Description SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution as root. A domain account with admin privileges and read and write access to the home directory is required. The impact is lower in Windows deployments.
Title SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Solarwinds Serv-u
cve-icon MITRE

Status: PUBLISHED

Assigner: SolarWinds

Published:

Updated: 2026-07-24T03:55:38.634Z

Reserved: 2026-02-26T14:15:09.403Z

Link: CVE-2026-28305

cve-icon Vulnrichment

Updated: 2026-07-22T18:09:26.804Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T17:30:17Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key