CVE-2026-28317: SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires domain administrator access. The impact is lower in Windows deployments.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SolarWinds Serv-Uto a version that resolves this vulnerability.Fixed in 2026.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28317?
The severity of CVE-2026-28317 is rated as critical with a score of 9.1.
What type of vulnerability is CVE-2026-28317?
CVE-2026-28317 is classified as an insecure direct object reference (IDOR) vulnerability.
How can CVE-2026-28317 lead to privilege escalation?
CVE-2026-28317 can allow unauthorized users to gain elevated permissions due to improper access controls.
What systems are affected by CVE-2026-28317?
SolarWinds Serv-U is the main software impacted by CVE-2026-28317.
What is the recommended response to CVE-2026-28317?
For CVE-2026-28317, it is essential to apply the latest security updates from SolarWinds to mitigate the vulnerability.