Description
SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. User authentication is required. The impact is lower in Windows deployments.
Published: 2026-07-21
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SolarWinds Serv‑U is affected by an insecure direct object reference vulnerability that allows an authenticated user to take control of another account by accessing resources they should not be able to reach. The weakness is classified as CWE‑639 and leads to account takeover, which could expose data and grant additional control over the system.

Affected Systems

SolarWinds Serv‑U in all affected deployments is vulnerable. Specific versions are not listed, but the vendor recommends upgrading to version 2026.3 to remediate the issue. The impact is lower in Windows deployments.

Risk and Exploitability

The CVSS score of 4.7 indicates moderate risk, and the EPSS score of less than 1% suggests exploitation is unlikely in the near term. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires valid authentication. Based on the description, it can be inferred that the IDOR flaw is triggered via the Serv‑U web interface, allowing a remote authenticated attacker to abuse the reference and obtain another user’s account.

Generated by OpenCVE AI on July 30, 2026 at 17:15 UTC.

Remediation

Vendor Solution

SolarWinds recommends customers upgrade to Serv-U version 2026.3 as soon as is practical.


OpenCVE Recommended Actions

  • Upgrade to Serv‑U version 2026.3.
  • Restrict access to user resources until the deployed version is confirmed to patch the ID account access attempts to detect residual exploitation attempts.
  • Implement network-level controls or temporary access restrictions to limit exposure of the Serv‑U web interface until the patch.

Generated by OpenCVE AI on July 30, 2026 at 17:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Solarwinds
Solarwinds serv-u
Vendors & Products Solarwinds
Solarwinds serv-u

Tue, 21 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Description SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. User authentication is required. The impact is lower in Windows deployments.
Title SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Solarwinds Serv-u
cve-icon MITRE

Status: PUBLISHED

Assigner: SolarWinds

Published:

Updated: 2026-07-24T03:55:45.575Z

Reserved: 2026-02-26T14:28:17.158Z

Link: CVE-2026-28314

cve-icon Vulnrichment

Updated: 2026-07-22T18:56:43.298Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T17:15:12Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key