Description
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrator access is required. The impact is lower in Windows deployments.
No analysis available yet.
Remediation
Vendor Solution
SolarWinds recommends customers to upgrade to Serv-U version 2026.3 as soon as is practical.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 21 Jul 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Solarwinds
Solarwinds serv-u |
|
| Vendors & Products |
Solarwinds
Solarwinds serv-u |
Tue, 21 Jul 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrator access is required. The impact is lower in Windows deployments. | |
| Title | SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: SolarWinds
Published:
Updated: 2026-07-21T15:34:40.127Z
Reserved: 2026-02-26T14:28:17.157Z
Link: CVE-2026-28308
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-21T23:30:03Z
Weaknesses
-
CWE-639
Authorization Bypass Through User-Controlled Key