CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-28302

Critical · CVSS 9.1
CVSS
9.1
nvd
EPSS
0.56%
43th pct
KEV
No
Class
other
CWE-639

Description

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root. This issue requires group administrator access. The impact is lower in Windows deployments.

References

Status: profiled · ingested 2026-07-24T18:00:18.000Z