Stored Cross-Site Scripting Vulnerability in SolarWinds Serv-U
CVE-2026-28315
6.2MEDIUM
What is CVE-2026-28315?
SolarWinds Serv-U is vulnerable to a stored cross-site scripting (XSS) attack, which could allow an attacker to execute arbitrary scripts in the context of an administrator's session. This security flaw can potentially lead to unauthorized access and the disclosure of sensitive information. Administrators are advised to apply security updates and mitigate risks to their systems.
Affected Version(s)
Serv-U Windows 15.5.4 HF1 and below