Critical severity9.1NVD Advisory· Published Jul 21, 2026· Updated Jul 24, 2026
CVE-2026-28308
CVE-2026-28308
Description
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrator access is required. The impact is lower in Windows deployments.
Affected products
2cpe:2.3:a:solarwinds:serv-u:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:solarwinds:serv-u:*:*:*:*:*:*:*:*range: <2026.3
- (no CPE)
Patches
Vulnerability mechanics
References
2- documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htmnvdRelease NotesVendor Advisory
- www.solarwinds.com/trust-center/security-advisories/CVE-2026-28308nvdVendor Advisory
News mentions
1- SolarWinds Patches 15 Critical Serv-U Flaws That Could Hand Attackers Root AccessCyber Security News · Jul 22, 2026