CVE-2026-28316: SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability to execute commands as the root user. This issue requires a domain account with administrator access. The impact is lower in Windows deployments.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SolarWinds Serv-Uto a version that resolves this vulnerability.Fixed in 2026.3 - Compensating control
Limit use of domain accounts with administrator access because the Serv-U IDOR issue requires a domain account with administrator access.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28316?
CVE-2026-28316 has a severity rating of 9.1, classified as critical.
What type of vulnerability is CVE-2026-28316?
CVE-2026-28316 is an Insecure Direct Object Reference (IDOR) vulnerability.
How do I fix CVE-2026-28316?
To fix CVE-2026-28316, ensure that all objects are properly verified before access and apply the latest patches provided by SolarWinds.
Who is affected by CVE-2026-28316?
CVE-2026-28316 affects users with domain accounts that have administrator access to SolarWinds Serv-U.
What is the potential impact of CVE-2026-28316?
The potential impact of CVE-2026-28316 includes privilege escalation to a system administrator, allowing execution of commands as the root user.