Junglewise Threat Intelligence

CVE-2026-28308: SolarWinds Serv-U IDOR remote code execution

CVE-2026-28308 · Severity: critical · CVSS 9.1 · Published 2026-07-21

Technologies: SolarWinds Serv-U. Vendors: SolarWinds.

Executive brief

SolarWinds Serv-U, a managed file transfer and FTP server, is affected by a security flaw that could allow an attacker to take full control of the server. To exploit this, an attacker must already have domain administrator privileges within the application. While the risk is lower for Windows-based installations, a successful attack could lead to unauthorized access to sensitive files, data theft, or a complete service shutdown.

Technical details

SolarWinds Serv-U contains an Insecure Direct Object Reference (IDOR) vulnerability (CWE-639) that facilitates remote code execution (RCE). The vulnerability exists due to improper authorization checks when accessing internal objects, allowing a user to manipulate identifiers to gain unauthorized access to system functions. Exploitation requires the attacker to possess high privileges (Domain Administrator). The impact is reportedly lower in Windows deployments compared to other operating systems. The issue is resolved in Serv-U version 2026.3.

Affected products

  • SolarWinds Serv-U 15.5.4 HF1 and below

Timeline

  • 2026-07-21: advisory: Initial advisory published by SolarWinds
  • 2026-07-21: patched: Fixed in Serv-U 2026.3

References

Related threats