Description
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability to execute commands as the root user. This issue requires a domain account with administrator access. The impact is lower in Windows deployments.
Published: 2026-07-21
Score: 4.7 Medium
EPSS: 1.3% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SolarWinds Serv‑U is vulnerable to an insecure direct object reference that allows an attacker who already has domain administrator privileges to elevate their privileges to system administrator and execute commands as the root user. The vulnerability arises when object references can be manipulated, bypassing access controls to reach protected resources. The impact is less severe on Windows deployments, but on affected systems an attacker can achieve full control of the host.

Affected Systems

The vulnerability affects SolarWinds Serv‑U. All releases prior to the recommended Serv‑U 2026.3 are susceptible; the CVE advisory specifically advises upgrading to 2026.3 to remediate the issue. No exact version list is provided, but any earlier Serv‑U build remains at risk.

Risk and Exploitability

The CVSS score of 4.7 denotes moderate severity, and the EPSS score of 1% indicates a low but nonzero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a domain account with administrator access, limiting the threat to internal actors or compromised administrator accounts. The attack vector is likely internal and involves manipulating direct object references within the application flow.

Generated by OpenCVE AI on August 4, 2026 at 05:36 UTC.

Remediation

Vendor Solution

SolarWinds recommends customers upgrade to Serv-U version 2026.3 as soon as is practical.


OpenCVE Recommended Actions

  • Apply the SolarWinds Serv‑U 2026.3 patch immediately.
  • Review and harden the configuration to restrict direct object references, ensuring administrative paths are not exposed to non‑administrative users.
  • Apply least‑privilege principles by reducing the number of domain accounts with administrator rights and regularly audit their usage.

Generated by OpenCVE AI on August 4, 2026 at 05:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Solarwinds
Solarwinds serv-u
Vendors & Products Solarwinds
Solarwinds serv-u

Tue, 21 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Description SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability to execute commands as the root user. This issue requires a domain account with administrator access. The impact is lower in Windows deployments.
Title SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Solarwinds Serv-u
cve-icon MITRE

Status: PUBLISHED

Assigner: SolarWinds

Published:

Updated: 2026-07-24T03:55:46.373Z

Reserved: 2026-02-26T14:28:17.158Z

Link: CVE-2026-28316

cve-icon Vulnrichment

Updated: 2026-07-21T17:43:09.952Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:45:03Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key