Insecure Direct Object Reference in SolarWinds Serv-U
CVE-2026-28316
4.7MEDIUM
What is CVE-2026-28316?
SolarWinds Serv-U is vulnerable to an insecure direct object reference (IDOR), which allows an attacker with an administrator domain account to escalate their privileges to that of a system administrator. This vulnerability poses a risk as it permits the execution of commands with root user privileges. It is important to note that the impact varies, with lower risk present in Windows environments. Users are advised to take necessary precautions and review security advisories for mitigation steps.
Affected Version(s)
Serv-U Windows 15.5.4 HF1 and below