SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root. This issue requires group administrator access. The impact is lower in Windows deployments.
Metrics
Affected Vendors & Products
References
History
Tue, 21 Jul 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Solarwinds
Solarwinds serv-u |
|
| Vendors & Products |
Solarwinds
Solarwinds serv-u |
Tue, 21 Jul 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root. This issue requires group administrator access. The impact is lower in Windows deployments. | |
| Title | SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: SolarWinds
Published:
Updated: 2026-07-21T15:31:30.297Z
Reserved: 2026-02-26T14:15:09.403Z
Link: CVE-2026-28302
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-21T23:30:03Z