A critical insecure direct object reference (IDOR) flaw in SolarWinds Serv-U can let an authenticated user take over another account, carrying a CVSS score of 9.1.
What Is It
CVE-2026-28314 is an insecure direct object reference vulnerability (CWE-639) in SolarWinds Serv-U. According to SolarWinds' PSIRT, the flaw "leads to an account takeover." User authentication is required to exploit it, and per the advisory the impact is lower in Windows deployments.
Why It Matters
The vulnerability is rated CRITICAL with a CVSS 3.1 base score of 9.1 (vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H). It is network-exploitable with low attack complexity and no user interaction, and its scope is Changed with High impact to confidentiality, integrity, and availability. Although exploitation requires existing (high-privilege) authentication, a successful attack results in account takeover; meaning an authenticated user could compromise other accounts. No CISA KEV entry was supplied, so active exploitation is not confirmed by KEV at this time.
What's Vulnerable
- Vendor: SolarWinds
- Product: Serv-U
- Affected versions: 15.5.4 HF1 and below
- Platforms: Windows and Linux (impact is lower on Windows deployments)
Patch Status
As of the NVD record (published 2026-07-21), the CVE is "Undergoing Analysis." SolarWinds has published a security advisory and Serv-U 2026-3 release notes; administrators should consult those SolarWinds sources for the fixed release and update affected Serv-U installations (15.5.4 HF1 and below) accordingly.
Sources
- SolarWinds Security Advisory; CVE-2026-28314: https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28314
- SolarWinds Serv-U 2026-3 Release Notes: https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm
- NVD, CVE-2026-28314: https://nvd.nist.gov/vuln/detail/CVE-2026-28314