PT-2026-61962 · Solarwinds · Serv-U

CVE-2026-28302

·

Published

2026-07-21

·

Updated

2026-07-24

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SolarWinds Serv-U (affected versions not specified)
Description An insecure direct object reference (IDOR) issue allows an attacker with group administrator access to achieve privilege escalation and remote code execution as root. IDOR is a type of access control flaw where an application provides direct access to objects based on user-supplied input. The impact of this issue is reduced in Windows deployments.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

RCE

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-14367
CVE-2026-28302

Affected Products

Serv-U