CVE-2026-28302: SolarWinds Serv-U IDOR Leads to Root RCE
ID: cd3e3c90-2e08-500d-8c27-b99670b10507
STIX ID: report--cd3e3c90-2e08-500d-8c27-b99670b10507
Feed Name: CosmicBytez Labs
**Executive Summary:** CVE-2026-28302 is a critical Insecure Direct Object Reference (IDOR) in SolarWinds Serv-U that allows a group administrator to manipulate object references to access privileged objects and chain that access to achieve root remote code execution on Linux (CVSS 9.1). Organizations should apply the vendor patch immediately, restrict and audit group-admin accounts, and monitor for IOCs such as unexpected root-level processes, new cron jobs, and outbound connections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
