Insecure Direct Object Reference Vulnerability in SolarWinds Serv-U
CVE-2026-28313
4.7MEDIUM
What is CVE-2026-28313?
SolarWinds Serv-U contains an insecure direct object reference vulnerability that may allow attackers to exploit SMTP functionality, potentially leading to unauthorized account takeover. This risk is particularly relevant, although the impact may be reduced in Windows-based deployments. Users are advised to review their configurations and apply any necessary updates to ensure their systems remain secure.
Affected Version(s)
Serv-U Windows 15.5.4 HF1 and below