Critical severity9.1NVD Advisory· Published Jul 21, 2026· Updated Jul 24, 2026
CVE-2026-28317
CVE-2026-28317
Description
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires domain administrator access. The impact is lower in Windows deployments.
Affected products
2cpe:2.3:a:solarwinds:serv-u:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:solarwinds:serv-u:*:*:*:*:*:*:*:*range: <2026.3
- (no CPE)
Patches
Vulnerability mechanics
References
2- documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htmnvdRelease NotesVendor Advisory
- www.solarwinds.com/trust-center/security-advisories/CVE-2026-28317nvdVendor Advisory
News mentions
2- ⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS HijacksThe Hacker News · Aug 3, 2026
- SolarWinds Patches 15 Critical Serv-U Flaws That Could Hand Attackers Root AccessCyber Security News · Jul 22, 2026