Serv-U MFT
by SolarWinds
CVEs (59)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-45714 | Med | 0.31 | 4.8 | 0.01 | Oct 16, 2024 | Application is vulnerable to Cross Site Scripting (XSS) an authenticated attacker with users’ permissions can modify a variable with a payload. | ||
| CVE-2020-22428 | Med | 0.31 | 4.8 | 0.01 | May 5, 2021 | SolarWinds Serv-U before 15.1.6 Hotfix 3 is affected by Cross Site Scripting (XSS) via a directory name (entered by an admin) containing a JavaScript payload. | ||
| CVE-2021-35249 | Med | 0.28 | 4.3 | 0.01 | May 17, 2022 | This broken access control vulnerability pertains specifically to a domain admin who can access configuration & user data of other domains which they should not have access to. Please note the admin is unable to modify the data (read only operation). This UAC issue leads to a… | ||
| CVE-2024-45712 | Low | 0.17 | 2.6 | 0.00 | Apr 15, 2025 | SolarWinds Serv-U is vulnerable to a client-side cross-site scripting (XSS) vulnerability. The vulnerability can only be performed by an authenticated account, on the local machine, from the local browser session. Therefore the risk is very low. | ||
| CVE-2026-28321 | Cri | 0.00 | 9.1 | 0.01 | Jul 21, 2026 | SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate privileges and execute code as root. A domain administrator access is required, and the impact is lower in Windows… | ||
| CVE-2026-28317 | Cri | 0.00 | 9.1 | 0.01 | Jul 21, 2026 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires domain administrator access. The impact is lower in Windows deployments. | ||
| CVE-2026-28316 | Cri | 0.00 | 9.1 | 0.02 | Jul 21, 2026 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability to execute commands as the root user. This issue requires a domain account with administrator access. The… | ||
| CVE-2026-28315 | Med | 0.00 | 6.2 | 0.01 | Jul 21, 2026 | SolarWinds Serv-U was found to be affected by a stored cross-site scripting vulnerability that could lead to session hijacking or information disclosure from an administrator account. | ||
| CVE-2026-28314 | Cri | 0.00 | 9.1 | 0.01 | Jul 21, 2026 | SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. User authentication is required. The impact is lower in Windows deployments. | ||
| CVE-2026-28313 | Cri | 0.00 | 9.1 | 0.01 | Jul 21, 2026 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary account takeover. The impact is lower in Windows deployments. | ||
| CVE-2026-28312 | Cri | 0.00 | 9.1 | 0.01 | Jul 21, 2026 | SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system administrator and allow code execution as root. The impact is lower in Windows deployments. | ||
| CVE-2026-28310 | Cri | 0.00 | 9.1 | 0.01 | Jul 21, 2026 | SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate their user type to that of a system administrator. The impact is lower in Windows deployments. | ||
| CVE-2026-28309 | Cri | 0.00 | 9.1 | 0.01 | Jul 21, 2026 | SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. The impact is lower in Windows deployments. | ||
| CVE-2026-28308 | Cri | 0.00 | 9.1 | 0.01 | Jul 21, 2026 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrator access is required. The impact is lower in Windows deployments. | ||
| CVE-2026-28307 | Cri | 0.00 | 9.1 | 0.01 | Jul 21, 2026 | SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator group. The impact is lower in Windows deployments. | ||
| CVE-2026-28306 | Cri | 0.00 | 9.1 | 0.01 | Jul 21, 2026 | SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system administrator. The impact is lower in Windows deployments. | ||
| CVE-2026-28305 | Cri | 0.00 | 9.1 | 0.01 | Jul 21, 2026 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution as root. A domain account with admin privileges and read and write access to the home directory is required. The impact is lower in Windows… | ||
| CVE-2026-28304 | Cri | 0.00 | 9.1 | 0.01 | Jul 21, 2026 | SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary execution of code remotely as root. The impact is lower in Windows deployments. | ||
| CVE-2026-28302 | Cri | 0.00 | 9.1 | 0.01 | Jul 21, 2026 | SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root. This issue requires group administrator access. The impact is lower in Windows deployments. |
- risk 0.31cvss 4.8epss 0.01
Application is vulnerable to Cross Site Scripting (XSS) an authenticated attacker with users’ permissions can modify a variable with a payload.
- risk 0.31cvss 4.8epss 0.01
SolarWinds Serv-U before 15.1.6 Hotfix 3 is affected by Cross Site Scripting (XSS) via a directory name (entered by an admin) containing a JavaScript payload.
- risk 0.28cvss 4.3epss 0.01
This broken access control vulnerability pertains specifically to a domain admin who can access configuration & user data of other domains which they should not have access to. Please note the admin is unable to modify the data (read only operation). This UAC issue leads to a…
- risk 0.17cvss 2.6epss 0.00
SolarWinds Serv-U is vulnerable to a client-side cross-site scripting (XSS) vulnerability. The vulnerability can only be performed by an authenticated account, on the local machine, from the local browser session. Therefore the risk is very low.
- risk 0.00cvss 9.1epss 0.01
SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate privileges and execute code as root. A domain administrator access is required, and the impact is lower in Windows…
- risk 0.00cvss 9.1epss 0.01
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires domain administrator access. The impact is lower in Windows deployments.
- risk 0.00cvss 9.1epss 0.02
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability to execute commands as the root user. This issue requires a domain account with administrator access. The…
- risk 0.00cvss 6.2epss 0.01
SolarWinds Serv-U was found to be affected by a stored cross-site scripting vulnerability that could lead to session hijacking or information disclosure from an administrator account.
- risk 0.00cvss 9.1epss 0.01
SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. User authentication is required. The impact is lower in Windows deployments.
- risk 0.00cvss 9.1epss 0.01
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary account takeover. The impact is lower in Windows deployments.
- risk 0.00cvss 9.1epss 0.01
SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system administrator and allow code execution as root. The impact is lower in Windows deployments.
- risk 0.00cvss 9.1epss 0.01
SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate their user type to that of a system administrator. The impact is lower in Windows deployments.
- risk 0.00cvss 9.1epss 0.01
SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. The impact is lower in Windows deployments.
- risk 0.00cvss 9.1epss 0.01
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrator access is required. The impact is lower in Windows deployments.
- risk 0.00cvss 9.1epss 0.01
SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator group. The impact is lower in Windows deployments.
- risk 0.00cvss 9.1epss 0.01
SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system administrator. The impact is lower in Windows deployments.
- risk 0.00cvss 9.1epss 0.01
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution as root. A domain account with admin privileges and read and write access to the home directory is required. The impact is lower in Windows…
- risk 0.00cvss 9.1epss 0.01
SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary execution of code remotely as root. The impact is lower in Windows deployments.
- risk 0.00cvss 9.1epss 0.01
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root. This issue requires group administrator access. The impact is lower in Windows deployments.
Page 3 of 3