CVE-2026-28315: SolarWinds Serv-U Authenticated Stored Cross-site Scripting (XSS) Vulnerability
SolarWinds Serv-U was found to be affected by a stored cross-site scripting vulnerability that could lead to session hijacking or information disclosure from an administrator account.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SolarWinds Serv-Uto a version that resolves this vulnerability.Fixed in 2026.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28315?
CVE-2026-28315 has a medium severity rating of 6.2.
What is CVE-2026-28315?
CVE-2026-28315 is a stored cross-site scripting vulnerability in SolarWinds Serv-U that can lead to session hijacking or information disclosure.
How do I fix CVE-2026-28315?
To fix CVE-2026-28315, apply the latest security patch provided by SolarWinds for Serv-U.
What are the potential impacts of CVE-2026-28315?
The potential impacts of CVE-2026-28315 include session hijacking and unauthorized access to sensitive information.
Who is affected by CVE-2026-28315?
The vulnerability affects users of SolarWinds Serv-U who have administrative access.