SYS::ONLINE
Wasteland.
Briefs1404
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-28308 2026-07-21

SolarWinds Serv-U IDOR Flaw (CVE-2026-28308) Enables Remote Code Execution

"SolarWinds Serv-U contains a critical insecure direct object reference (IDOR) vulnerability, tracked as CVE-2026-28308, that can lead to remote code execution and carries a CVSS score of 9.1."

SolarWinds Serv-U contains a critical insecure direct object reference (IDOR) vulnerability, tracked as CVE-2026-28308, that can lead to remote code execution and carries a CVSS score of 9.1.

What Is It

CVE-2026-28308 is an insecure direct object reference (IDOR) vulnerability in SolarWinds Serv-U, classified under CWE-639. According to the NVD record, the flaw can lead to remote code execution. Exploitation requires domain administrator access, and the impact is lower in Windows deployments. The CVSS 3.1 vector (AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H) reflects a network-reachable, low-complexity flaw that requires high privileges, needs no user interaction, and results in a scope change with high confidentiality, integrity, and availability impact.

Why It Matters

With a base score of 9.1, the vulnerability is rated CRITICAL. The scope-changed vector combined with full high-impact ratings across confidentiality, integrity, and availability means a successful exploit can extend beyond the initially vulnerable component. The path to remote code execution makes this a serious risk for exposed Serv-U deployments, even though the high-privilege requirement (domain administrator access) constrains who can trigger it.

What's Vulnerable

The affected product is SolarWinds Serv-U. Per the vendor advisory data, versions 15.5.4 HF1 and below are affected; the default status for other versions is listed as unaffected. The NVD record notes the impact is lower in Windows deployments.

Patch Status

This CVE is not listed in the supplied CISA KEV data, so there is no KEV confirmation of active exploitation. The NVD entry is currently "Undergoing Analysis" (published 2026-07-21). SolarWinds has issued a security advisory and release notes for the affected product; administrators should consult those vendor resources for remediation guidance and upgrade information for versions above 15.5.4 HF1.

Sources