Insecure Direct Object Reference in SolarWinds Serv-U
CVE-2026-28308

4.7MEDIUM

Key Information:

Vendor

Solarwinds

Status
Vendor
CVE Published:
21 July 2026

What is CVE-2026-28308?

SolarWinds Serv-U is impacted by an insecure direct object reference (IDOR) vulnerability, which could enable remote code execution under specific circumstances. This vulnerability requires domain administrator access to exploit. Notably, the risk is considered lower on Windows system deployments. Organizations using affected versions of Serv-U should take immediate action to mitigate the risk and consult the security advisories provided by SolarWinds for comprehensive guidance.

Affected Version(s)

Serv-U 15.5.4 HF1 and below

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Intigriti Bug Bounty Program
.