Junglewise Threat Intelligence

CVE-2026-28315: SolarWinds Serv-U stored XSS in administrator interface

CVE-2026-28315 · Severity: medium · CVSS 6.2 · Published 2026-07-21

Technologies: SolarWinds Serv-U. Vendors: SolarWinds.

Executive brief

SolarWinds Serv-U, a managed file transfer solution, is affected by a security flaw that could allow an attacker to inject malicious scripts into the application. If an administrator views the affected area, the attacker could hijack their session or steal sensitive information. This could lead to unauthorized access to the file transfer system and the data it manages.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in SolarWinds Serv-U versions 15.5.4 HF1 and below. The flaw (CWE-79) allows a remote attacker with high privileges to inject malicious scripts into the web interface. When an administrative user interacts with the compromised component, the script executes in their browser context, potentially leading to session hijacking or sensitive information disclosure. The vulnerability is addressed in Serv-U version 2026.3.

Affected products

  • SolarWinds Serv-U 15.5.4 HF1 and below

Timeline

  • 2026-07-21: advisory
  • 2026-07-21: disclosed
  • 2026-07-21: patched: Fixed in version 2026.3

References

Related threats