CVE-2026-28308: SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrator access is required. The impact is lower in Windows deployments.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SolarWinds Serv-Uto a version that resolves this vulnerability.Fixed in 2026.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28308?
CVE-2026-28308 has a critical severity rating of 9.1.
What type of vulnerability is CVE-2026-28308?
CVE-2026-28308 is classified as an insecure direct object reference (IDOR) vulnerability.
What are the potential impacts of CVE-2026-28308?
CVE-2026-28308 can lead to remote code execution and may result in unauthorized access to sensitive data.
How can I mitigate the risks associated with CVE-2026-28308?
To mitigate CVE-2026-28308, ensure that access controls are properly implemented and review user permissions.
Is there a specific user requirement for exploiting CVE-2026-28308?
Exploiting CVE-2026-28308 requires domain administrator access.