CVE-2026-28302
serv-u: Authorization Bypass Through User-Controlled Key (CVE-2026-28302)
Beschreibung
SolarWinds Serv-U ist von einer unsicheren direkten Objektreferenz (IDOR)-Sicherheitslücke betroffen, die zu einer Privilegserhöhung und der Ausführung von Code als Root-Rechte aus der Ferne führen kann. Dieses Problem erfordert Administratorzugriff auf eine Gruppe. Die Auswirkungen sind in Windows-Installationen geringer. ---
Metriken
Weakness-Klassen (CWE)
CWE-639Base
Authorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
cwe.mitre.org →
Re-Analyse & Statuswechsel
Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.
- CVE Modified2026-07-24 05:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-28302","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI… → {"id":"CVE-2026-28302","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
- CVE Modified2026-07-22 19:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-28302","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
- New CVE Received2026-07-21 16:17 UTC· psirt@solarwinds.com
- Affected: Serv-U
- Description: SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root. This issue requires group administrator access. The impact is lower in Windows deployments.
- CVSS V3.1: AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- CWE: CWE-639
Betroffene Produkte
Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.
solarwinds
serv-u2026.3