CVE-2026-28313: SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary account takeover. The impact is lower in Windows deployments.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SolarWinds Serv-Uto a version that resolves this vulnerability.Fixed in 2026.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28313?
CVE-2026-28313 has a critical severity rating of 9.1.
How do I fix CVE-2026-28313?
To mitigate CVE-2026-28313, update SolarWinds Serv-U to the latest version that addresses this vulnerability.
What systems are affected by CVE-2026-28313?
CVE-2026-28313 affects all versions of SolarWinds Serv-U, with a slightly lower impact noted in Windows deployments.
What type of vulnerability is CVE-2026-28313?
CVE-2026-28313 is classified as an insecure direct object reference (IDOR) vulnerability.
What could be the consequences of exploiting CVE-2026-28313?
Exploitation of CVE-2026-28313 could lead to SMTP hijacking and arbitrary account takeover.