Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4501 articles · 223839 vulns · 37/41 feeds (7d)
← Back to list
9.1
CVE-2026-28305PATCHED
solarwinds · serv-u

SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability

Description

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution as root. A domain account with admin privileges and read and write access to the home directory is required. The impact is lower in Windows deployments.

Affected Products

VendorProductVersions
solarwindsserv-u15.5.4 HF1 and below

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
solarwindsserv-ucert_advisory90%

References

  • https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28305(vendor-advisory)
  • https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm

Related News (3 articles)

Tier B
BSI Advisories67d ago
[NEU] [hoch] SolarWinds Serv-U: Mehrere Schwachstellen
→ No new info (linked only)
Tier D
Heise Security67d ago
Datentransfersoftware Serv-U hat 15 kritische Sicherheitslücken
→ No new info (linked only)
Tier C
VulDB68d ago
CVE-2026-28305 | SolarWinds Serv-U Home resource injection
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.19.1 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28305
CWECWE-639
PublishedJul 21, 2026
Trending Score0
Source articles3
Independent3
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-28324
SolarWinds Observability Self-Hosted Remote Code Execution Vulnerability
Trending: 44
HIGHCVE-2026-28326
SolarWinds Access Rights Manager Unauthenticated Remote Code Execution Vulnerability
Trending: 38
HIGHCVE-2026-28325
SolarWinds Observability Self-Hosted Unauthenticated Remote Code Execution Vulnerability
Trending: 35
MEDIUMCVE-2026-28315
SolarWinds Serv-U Authenticated Stored Cross-site Scripting (XSS) Vulnerability
CRITICALCVE-2026-28302
SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 21, 2026
Discovered by ZDM
Jul 21, 2026
Patch Available
Jul 24, 2026