Insecure Direct Object Reference in SolarWinds Serv-U
CVE-2026-28317
4.7MEDIUM
What is CVE-2026-28317?
SolarWinds Serv-U contains an insecure direct object reference vulnerability allowing potential privilege escalation. Successful exploitation necessitates domain administrator access, primarily affecting environments deployed on Windows. The issue highlights the importance of secure access controls to mitigate unauthorized privilege escalations.
Affected Version(s)
Serv-U Windows 15.5.4 HF1 and below