logo

CVE-2026-28302: SolarWinds Serv-U IDOR Leads to Root RCE

ID: cd3e3c90-2e08-500d-8c27-b99670b10507

STIX ID: report--cd3e3c90-2e08-500d-8c27-b99670b10507

Feed Name: CosmicBytez Labs

Threat Score
88/100

Date Published: 2026-07-22

Date Updated: 2026-07-23

...
...

**Executive Summary:** CVE-2026-28302 is a critical Insecure Direct Object Reference (IDOR) in SolarWinds Serv-U that allows a group administrator to manipulate object references to access privileged objects and chain that access to achieve root remote code execution on Linux (CVSS 9.1). Organizations should apply the vendor patch immediately, restrict and audit group-admin accounts, and monitor for IOCs such as unexpected root-level processes, new cron jobs, and outbound connections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.