Description
SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. User authentication is required. The impact is lower in Windows deployments.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
SolarWinds recommends customers upgrade to Serv-U version 2026.3 as soon as is practical.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 21 Jul 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. User authentication is required. The impact is lower in Windows deployments. | |
| Title | SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: SolarWinds
Published:
Updated: 2026-07-21T15:38:39.779Z
Reserved: 2026-02-26T14:28:17.158Z
Link: CVE-2026-28314
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses