CVE-2026-28316

Published: Lug 21, 2026 Last Modified: Lug 24, 2026
ExploitDB:
Other exploit source:
Google Dorks:
CRITICAL 9,1
Attack Vector: network
Attack Complexity: low
Privileges Required: high
User Interaction: none
Scope: changed
Confidentiality: high
Integrity: high
Availability: high

Description

AI Translation Available

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability to execute commands as the root user. This issue requires a domain account with administrator access. The impact is lower in Windows deployments.

639

Authorization Bypass Through User-Controlled Key

Incomplete
Common Consequences
Security Scopes Affected:
Access Control
Potential Impacts:
Bypass Protection Mechanism Gain Privileges Or Assume Identity
Applicable Platforms
All platforms may be affected
View CWE Details
Application

Serv-U by Solarwinds

Version Range Affected
To 2026.3 (exclusive)
cpe:2.3:a:solarwinds:serv-u:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://documentation.solarwinds.com/en/success_center/servu/content/release_no…
https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28316