CVE-2026-28313
SolarWinds Serv‑U has a critical insecure direct object reference flaw that lets attackers hijack SMTP and take over user accounts. The weakness is most severe on non‑Windows deployments. No public exploit is known yet.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
SolarWinds Serv‑U installations, especially on non‑Windows platforms. Administrators and users of the affected software are at risk.
Real-world impact
An attacker who exploits the IDOR can hijack the SMTP service and gain control of any user account, potentially accessing sensitive data or using the system to send spam.
Why this severity
The CVSS score of 9.1 reflects the high impact (confidentiality, integrity, availability) and the fact that the vulnerability can be exploited remotely with low effort, even though it requires high privileges to fully abuse.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Jul 21, 2026 · 11d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 8d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- documentation.solarwinds.com/en/success_center/servu/con…release notesvendor advisory
- https//www.solarwinds.com/trust-c…vendor advisory