cbcvebase.
CVE-2026-28302
published 2026-07-21

CVE-2026-28302: SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as…

PriorityP358critical9.1CVSS 3.1
AVNACLPRHUINSCCHIHAH
EPSS
0.72%
52.3th percentile
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root. This issue requires group administrator access. The impact is lower in Windows deployments.

Affected

2 ranges
VendorProductVersion rangeFixed in
solarwindsserv-u< 2026.32026.3
solarwindsserv-u——
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.