← All CVEs

CVE-2026-28308

critical · 9.1

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrator access is required. The impact is lower in Windows deployments.

9.1
CVSS
0.8%
EPSS (exploit prob.)
55th
EPSS percentile
2026-07-21
Published

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-639

Affected products

VendorProductAffected versions
solarwindsserv-u< 2026.3

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2026-28308