Description
SolarWinds Serv-U was found to be affected by a stored cross-site scripting vulnerability that could lead to session hijacking or information disclosure from an administrator account.
Published: 2026-07-21
Score: 6.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SolarWinds Serv‑U is vulnerable to a stored cross‑site scripting flaw that can be abused by authenticated administrators. An attacker who can inject crafted input into the application may cause a victim’s browser to execute malicious script in the context of the administrator account, potentially allowing session hijacking and the leakage of sensitive information.

Affected Systems

The vulnerability affects SolarWinds Serv‑U for authenticated administrators who can log in and enter data into the web interface. The issue is present in versions prior to the release of Serv‑U 2026.3; exact version ranges are not enumerated in the advisory, instances should be evaluated for the presence of the flaw.

Risk and Exploitability

The CVSS score of 6.2 reflects a medium impact for a user with administrative access. The EPSS score indicates a very low exploitation probability at present (<1%). The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through normal authenticated usage of the Serv‑U application, where an attacker can store malicious script data that later executes when an administrator views the affected content.

Generated by OpenCVE AI on July 30, 2026 at 17:14 UTC.

Remediation

Vendor Solution

SolarWinds recommends customers upgrade to Serv-U version 2026.3 as soon as is practical.


OpenCVE Recommended Actions

  • Upgrade Serv‑U to version 2026.3 or later as recommended by SolarWinds
  • Ensure that all user‑provided input is properly encoded or sanitized to prevent XSS injection
  • Limit administrator privileges and employ least‑privilege access controls to reduce exposure

Generated by OpenCVE AI on July 30, 2026 at 17:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Solarwinds
Solarwinds serv-u
Vendors & Products Solarwinds
Solarwinds serv-u

Tue, 21 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Description SolarWinds Serv-U was found to be affected by a stored cross-site scripting vulnerability that could lead to session hijacking or information disclosure from an administrator account.
Title SolarWinds Serv-U Authenticated Stored Cross-site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N'}


Subscriptions

Solarwinds Serv-u
cve-icon MITRE

Status: PUBLISHED

Assigner: SolarWinds

Published:

Updated: 2026-07-21T17:44:05.421Z

Reserved: 2026-02-26T14:28:17.158Z

Link: CVE-2026-28315

cve-icon Vulnrichment

Updated: 2026-07-21T17:44:01.107Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T17:15:12Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')