Insecure Direct Object Reference Vulnerability in SolarWinds Serv-U
CVE-2026-28314
4.7MEDIUM
What is CVE-2026-28314?
The vulnerability in SolarWinds Serv-U allows an attacker to exploit an insecure direct object reference, leading to potential account takeover. This issue necessitates user authentication, with a notably lower impact on Windows deployments. Organizations using affected versions should prioritize applying security advisories and updates to mitigate any risks associated with this vulnerability.
Affected Version(s)
Serv-U Windows 15.5.4 HF1 and below