CVE-2026-28305: SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution as root. A domain account with admin privileges and read and write access to the home directory is required. The impact is lower in Windows deployments.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SolarWinds Serv-Uto a version that resolves this vulnerability.Fixed in 2026.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28305?
CVE-2026-28305 has a critical severity rating of 9.1.
How do I fix CVE-2026-28305?
To mitigate CVE-2026-28305, ensure that all admin accounts have appropriate permissions and implement access controls.
What systems are affected by CVE-2026-28305?
CVE-2026-28305 affects SolarWinds Serv-U, particularly in configurations with domain accounts that have admin privileges.
What are the potential consequences of CVE-2026-28305?
The vulnerability could lead to remote code execution as root, potentially compromising the entire system.
Is the impact of CVE-2026-28305 lower on any operating system?
Yes, the impact of CVE-2026-28305 is reported to be lower in Windows deployments.