Vulnerability Intelligence Report
SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability
CVE-2026-28316
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability to execute commands as the root user. This issue requires a domain account with administrator access. The impact is lower in Windows deployments.
No Active Exploit Signals
CVSS Base Score
9.1
CRITICAL
Exploitability:2.3
Impact Score:6.1
EPSS Probability:1.28%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-639 ↗CWE-639 Authorization Bypass Through User-Controlled Key
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| SolarWinds | Serv-U | 15.5.4 HF1 and below (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
1.280%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | SolarWinds · Vendor · USA |
| Reserved | 2026-02-26T14:28:17 |
| Published | 2026-07-21T15:39:17 |
| Last Updated | 2026-07-24T03:55:46 |
Community Chatter & Buzz