Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4508 articles · 223849 vulns · 37/41 feeds (7d)
← Back to list
9.1
CVE-2026-28302PATCHED
solarwinds · serv-u

SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability

Description

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root. This issue requires group administrator access. The impact is lower in Windows deployments.

Affected Products

VendorProductVersions
solarwindsserv-u15.5.4 HF1 and below

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
solarwindsserv-ucert_advisory90%

References

  • https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28302(vendor-advisory)
  • https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm(release-notes)

Related News (3 articles)

Tier B
BSI Advisories67d ago
[NEU] [hoch] SolarWinds Serv-U: Mehrere Schwachstellen
→ No new info (linked only)
Tier D
Heise Security67d ago
Datentransfersoftware Serv-U hat 15 kritische Sicherheitslücken
→ No new info (linked only)
Tier C
VulDB68d ago
CVE-2026-28302 | SolarWinds Serv-U resource injection
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.19.1 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28302
CWECWE-639
PublishedJul 21, 2026
Trending Score0
Source articles3
Independent3
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-28324
SolarWinds Observability Self-Hosted Remote Code Execution Vulnerability
Trending: 44
HIGHCVE-2026-28326
SolarWinds Access Rights Manager Unauthenticated Remote Code Execution Vulnerability
Trending: 37
HIGHCVE-2026-28325
SolarWinds Observability Self-Hosted Unauthenticated Remote Code Execution Vulnerability
Trending: 35
MEDIUMCVE-2026-28315
SolarWinds Serv-U Authenticated Stored Cross-site Scripting (XSS) Vulnerability
CRITICALCVE-2026-28305
SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 21, 2026
Discovered by ZDM
Jul 21, 2026
Patch Available
Jul 24, 2026