CVE-2026-28314: SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability
SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. User authentication is required. The impact is lower in Windows deployments.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SolarWinds Serv-Uto a version that resolves this vulnerability.Fixed in 2026.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28314?
The severity of CVE-2026-28314 is rated as critical with a CVSS score of 9.1.
What is the risk associated with CVE-2026-28314?
CVE-2026-28314 has a risk score of 72, indicating a high level of risk for users.
How can CVE-2026-28314 be exploited?
CVE-2026-28314 can be exploited through insecure direct object reference, potentially leading to account takeover.
Is authentication required to exploit CVE-2026-28314?
Yes, user authentication is required to exploit CVE-2026-28314.
What deployment environments are affected by CVE-2026-28314?
CVE-2026-28314 affects SolarWinds Serv-U deployments, with a lower impact noted on Windows environments.