Description
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrator access is required. The impact is lower in Windows deployments.
Published: 2026-07-21
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SolarWinds Serv-U is vulnerable to an insecure direct object reference that permits an attacker to manipulate URL parameters and gain access to files or commands outside the intended scope. This weakness can ultimately lead to the execution of arbitrary code on the server, granting full control over the affected system. The flaw is listed as CWE-639, indicating that it arises from improper authorization checks on object references.

Affected Systems

The affected product is SolarWinds Serv-U, and the CVE does not specify which versions are impacted; however, the advisory recommends upgrading to 2026.3. The flaw is particularly relevant for deployments where the application is installed on Windows servers and accessed by domain administrators, though the impact is lower when Serv-U runs under a restricted, non-domain realm account.

Risk and Exploitability

The CVSS score of 4.7 reflects a moderate risk, but the requirement for domain administrator credentials limits the attack surface. The EPSS score of less than 1% indicates a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, because the flaw can result in remote code execution if harnessed, it should be treated as a priority for patching, especially in environments where Serv-U services are exposed to internal or external networks.

Generated by OpenCVE AI on July 30, 2026 at 17:17 UTC.

Remediation

Vendor Solution

SolarWinds recommends customers to upgrade to Serv-U version 2026.3 as soon as is practical.


OpenCVE Recommended Actions

  • Upgrade Serv-U to version 2026.3 or later as soon as practicable.
  • Verify that the upgraded deployment is run under a non-privileged service account and that only authorized users have administrative access to the Serv-U control panel.
  • Review and tighten file and directory permissions for all user-submitted content to ensure that only intended objects are accessible through the web interface.

Generated by OpenCVE AI on July 30, 2026 at 17:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Solarwinds
Solarwinds serv-u
Vendors & Products Solarwinds
Solarwinds serv-u

Tue, 21 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Description SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrator access is required. The impact is lower in Windows deployments.
Title SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Solarwinds Serv-u
cve-icon MITRE

Status: PUBLISHED

Assigner: SolarWinds

Published:

Updated: 2026-07-24T03:55:41.194Z

Reserved: 2026-02-26T14:28:17.157Z

Link: CVE-2026-28308

cve-icon Vulnrichment

Updated: 2026-07-22T18:48:26.018Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T17:30:17Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key