SYS::ONLINE
Wasteland.
Briefs1410
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-28314 2026-07-21

CVE-2026-28314: SolarWinds Serv-U Account Takeover via Insecure Direct Object Reference

"A critical insecure direct object reference (IDOR) flaw in SolarWinds Serv-U can let an authenticated user take over another account, carrying a CVSS score of 9.1."

A critical insecure direct object reference (IDOR) flaw in SolarWinds Serv-U can let an authenticated user take over another account, carrying a CVSS score of 9.1.

What Is It

CVE-2026-28314 is an insecure direct object reference vulnerability (CWE-639) in SolarWinds Serv-U. According to SolarWinds' PSIRT, the flaw "leads to an account takeover." User authentication is required to exploit it, and per the advisory the impact is lower in Windows deployments.

Why It Matters

The vulnerability is rated CRITICAL with a CVSS 3.1 base score of 9.1 (vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H). It is network-exploitable with low attack complexity and no user interaction, and its scope is Changed with High impact to confidentiality, integrity, and availability. Although exploitation requires existing (high-privilege) authentication, a successful attack results in account takeover; meaning an authenticated user could compromise other accounts. No CISA KEV entry was supplied, so active exploitation is not confirmed by KEV at this time.

What's Vulnerable

Patch Status

As of the NVD record (published 2026-07-21), the CVE is "Undergoing Analysis." SolarWinds has published a security advisory and Serv-U 2026-3 release notes; administrators should consult those SolarWinds sources for the fixed release and update affected Serv-U installations (15.5.4 HF1 and below) accordingly.

Sources