CVE-2026-28308

Summary

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrator access is required. The impact is lower in Windows deployments.

Affected Software

VendorProductVersion RangeStatus
SolarWindsServ-U15.5.4 HF1 and belowaffected

Weaknesses

  • CWE-639: CWE-639 Authorization Bypass Through User-Controlled Key

References