SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires domain administrator access. The impact is lower in Windows deployments.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
SolarWinds recommends customers upgrade to Serv-U version 2026.3 as soon as is practical.
Workaround
No workaround given by the vendor.
References
History
Tue, 21 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 21 Jul 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires domain administrator access. The impact is lower in Windows deployments. | |
| Title | SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: SolarWinds
Published:
Updated: 2026-07-21T17:36:54.334Z
Reserved: 2026-02-26T14:46:41.520Z
Link: CVE-2026-28317
Updated: 2026-07-21T17:33:03.443Z
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses