SolarWinds Serv-U was found to be affected by a stored cross-site scripting vulnerability that could lead to session hijacking or information disclosure from an administrator account.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
SolarWinds recommends customers upgrade to Serv-U version 2026.3 as soon as is practical.
Workaround
No workaround given by the vendor.
References
History
Tue, 21 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 21 Jul 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SolarWinds Serv-U was found to be affected by a stored cross-site scripting vulnerability that could lead to session hijacking or information disclosure from an administrator account. | |
| Title | SolarWinds Serv-U Authenticated Stored Cross-site Scripting (XSS) Vulnerability | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: SolarWinds
Published:
Updated: 2026-07-21T17:44:05.421Z
Reserved: 2026-02-26T14:28:17.158Z
Link: CVE-2026-28315
Updated: 2026-07-21T17:44:01.107Z
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses