CVE-2026-28316

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability to execute commands as the root user. This issue requires a domain account with administrator access. The impact is lower in Windows deployments.
Configurations

No configuration.

History

21 Jul 2026, 16:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-21 16:17

Updated : 2026-07-24 05:16


NVD link : CVE-2026-28316

Mitre link : CVE-2026-28316

CVE.ORG link : CVE-2026-28316


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key