Junglewise Threat Intelligence

CVE-2026-28314: SolarWinds Serv-U account takeover via IDOR

CVE-2026-28314 · Severity: critical · CVSS 9.1 · Published 2026-07-21

Technologies: SolarWinds Serv-U. Vendors: SolarWinds.

Executive brief

SolarWinds Serv-U, a managed file transfer and FTP server, is affected by a security flaw that allows an authenticated user to take over other user accounts. By exploiting this vulnerability, an attacker could gain unauthorized access to sensitive files and administrative controls. The business impact is highest on Linux deployments, while Windows-based installations are less severely affected.

Technical details

SolarWinds Serv-U (version 15.5.4 HF1 and below) contains an Insecure Direct Object Reference (IDOR) vulnerability, classified as CWE-639. The flaw allows an authenticated attacker with high privileges to bypass authorization checks by manipulating user-controlled keys, ultimately leading to a complete account takeover. The attack vector is network-based and does not require user interaction, though it does require prior authentication. While the vulnerability is present on both Windows and Linux platforms, the vendor notes the impact is lower in Windows deployments. A fix is available in Serv-U version 2026.3.

Affected products

  • SolarWinds Serv-U 15.5.4 HF1 and below

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats