← All CVEs

CVE-2026-28317

critical · 9.1

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires domain administrator access. The impact is lower in Windows deployments.

9.1
CVSS
0.5%
EPSS (exploit prob.)
42nd
EPSS percentile
2026-07-21
Published

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-639

Affected products

VendorProductAffected versions
solarwindsserv-u< 2026.3

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2026-28317