SYS::ONLINE
Wasteland.
Briefs1404
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-28302 2026-07-21

CVE-2026-28302: SolarWinds Serv-U IDOR Enables Root-Level RCE

"A critical insecure direct object reference flaw in SolarWinds Serv-U lets an authenticated group administrator escalate privileges and execute code as root on Linux deployments."

A critical insecure direct object reference flaw in SolarWinds Serv-U lets an authenticated group administrator escalate privileges and execute code as root on Linux deployments.

What Is It

CVE-2026-28302 is an insecure direct object reference (IDOR) vulnerability in SolarWinds Serv-U, classified under CWE-639. According to SolarWinds, the flaw can lead to privilege escalation and remote code execution as root. Exploitation requires group administrator access to the affected system. The vulnerability carries a CVSS 3.1 base score of 9.1 (Critical), with the vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H, network-reachable, low attack complexity, requiring high privileges, no user interaction, and a changed scope with high confidentiality, integrity, and availability impact.

Why It Matters

The vulnerability results in full root-level remote code execution, giving an attacker complete control over the underlying host. Because the scope is "changed," a compromise extends beyond the vulnerable component itself. SolarWinds notes that the impact is lower in Windows deployments, making Linux installations the primary concern. While attacker prerequisites include group administrator access, the combination of a network attack vector and root-level code execution places this at the top of the severity scale.

What's Vulnerable

The affected product is SolarWinds Serv-U, version 15.5.4 HF1 and below, across both Windows and Linux platforms. Per the vendor advisory, the impact is lower in Windows deployments; Linux systems face the full root-level RCE risk.

Patch Status

The vulnerability was published on 2026-07-21 and its NVD status is "Awaiting Analysis." No CISA KEV entry was supplied, so there is no confirmation of active exploitation at this time. SolarWinds has published a security advisory and release notes (referenced below); organizations running Serv-U 15.5.4 HF1 or earlier should consult the vendor advisory and upgrade to a fixed release.

Sources