SYS::ONLINE
Wasteland.
Briefs1402
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-28313 2026-07-21

CVE-2026-28313: Critical IDOR in SolarWinds Serv-U Enables Account Takeover

"SolarWinds Serv-U contains a critical insecure direct object reference flaw that can be abused to hijack SMTP functionality and take over arbitrary accounts."

SolarWinds Serv-U contains a critical insecure direct object reference flaw that can be abused to hijack SMTP functionality and take over arbitrary accounts.

What Is It

CVE-2026-28313 is an insecure direct object reference (IDOR) vulnerability (CWE-639) in SolarWinds Serv-U. According to the vendor advisory, the flaw can lead to SMTP hijacking that results in arbitrary account takeover. The impact is lower in Windows deployments. It carries a CVSS 3.1 base score of 9.1 (CRITICAL), with the vector AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H, network-reachable, low attack complexity, no user interaction, and high impact across confidentiality, integrity, and availability with a changed scope.

Why It Matters

Serv-U is a managed file transfer and file-serving product often exposed to networks for remote access, making it an attractive target. The changed scope and full high-impact triad mean a successful exploit does not stay contained to the attacker's own privileges; it can pivot into other accounts. Account takeover via SMTP hijacking gives an attacker a foothold that can undermine the confidentiality and integrity of hosted data. While the attack requires high privileges to begin, the network attack vector and low complexity keep the barrier to exploitation modest for an authenticated actor.

What's Vulnerable

The affected product is SolarWinds Serv-U on both Windows and Linux platforms. Per the NVD record, versions 15.5.4 HF1 and below are affected. Windows deployments are noted by the vendor as experiencing lower impact than Linux.

Patch Status

This CVE was published on 2026-07-21 and is currently in "Undergoing Analysis" status at NVD. It does not appear in the supplied CISA KEV data, so there is no confirmation of active exploitation at this time. SolarWinds has issued a security advisory and documented the fix in the Serv-U 2026.3 release notes; administrators running 15.5.4 HF1 or earlier should upgrade to the fixed release per the vendor guidance.

Sources