← Back to CVE List
Vulnerability Intelligence Report
SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability

CVE-2026-28316

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability to execute commands as the root user. This issue requires a domain account with administrator access. The impact is lower in Windows deployments.

No Active Exploit Signals
CVSS Base Score
9.1
CRITICAL
Exploitability:2.3
Impact Score:6.1
EPSS Probability:1.28%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-639 ↗CWE-639 Authorization Bypass Through User-Controlled Key

Affected Products & Versions

Vendor Product Affected Versions
SolarWinds Serv-U 15.5.4 HF1 and below (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
1.280%

Identity & Timeline

StatusPUBLISHED
Assigning AuthoritySolarWinds · Vendor · USA
Reserved2026-02-26T14:28:17
Published2026-07-21T15:39:17
Last Updated2026-07-24T03:55:46

LINK COPIED TO CLIPBOARD