SYS::ONLINE
Wasteland.
Briefs1410
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-28305 2026-07-21

CVE-2026-28305: Critical IDOR in SolarWinds Serv-U Leads to Root RCE

"SolarWinds Serv-U file transfer software contains an insecure direct object reference (IDOR) vulnerability, rated CVSS 9.1 Critical, that can escalate an authenticated admin account into remote code execution as root."

SolarWinds Serv-U file transfer software contains an insecure direct object reference (IDOR) vulnerability, rated CVSS 9.1 Critical, that can escalate an authenticated admin account into remote code execution as root.

What Is It

CVE-2026-28305 is an insecure direct object reference (IDOR) flaw (CWE-639) in SolarWinds Serv-U. According to SolarWinds' PSIRT, the vulnerability can lead to remote code execution as root. Exploitation requires a domain account with admin privileges and read/write access to the home directory. The impact is lower in Windows deployments than on Linux.

The CVSS 3.1 base score is 9.1 (Critical), with the vector AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H, network-reachable, low attack complexity, high privileges required, no user interaction, and a changed scope with high confidentiality, integrity, and availability impact.

Why It Matters

Serv-U is a widely deployed managed file transfer product, and its history has made it a repeated target. A network-facing flaw that yields root-level code execution, crossing a privilege scope boundary, gives an attacker who already holds admin-level access full control of the underlying host. The elevated impact on Linux deployments makes those systems the priority for remediation.

What's Vulnerable

Patch Status

The CVE record is currently in "Awaiting Analysis" status at NVD, published July 21, 2026. SolarWinds has issued a security advisory and 2026-3 release notes (linked below); administrators should consult those official sources for fixed-version and upgrade guidance. No CISA KEV entry was supplied with this record, so active exploitation is not confirmed in the available source material.

Sources