Stored Cross-Site Scripting Vulnerability in SolarWinds Serv-U
CVE-2026-28315

6.2MEDIUM

Key Information:

Vendor

Solarwinds

Status
Vendor
CVE Published:
21 July 2026

What is CVE-2026-28315?

SolarWinds Serv-U is vulnerable to a stored cross-site scripting (XSS) attack, which could allow an attacker to execute arbitrary scripts in the context of an administrator's session. This security flaw can potentially lead to unauthorized access and the disclosure of sensitive information. Administrators are advised to apply security updates and mitigate risks to their systems.

Affected Version(s)

Serv-U Windows 15.5.4 HF1 and below

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.