ctipilot.ch

SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE)

cve · CVE-2026-28311

Coverage timeline
1
first 2026-07-23 → last 2026-07-23
Peak priority
notable
1 notable
Sources cited
4
4 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
8
see Related entities below
ATT&CK techniques
1
pinned v19.1 · see below

Hunting pivots

ATT&CK techniques
Affected products
SolarWinds Serv-U

ATT&CK techniques

1 technique observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Privilege Escalation TA0004

T1068Exploitation for Privilege Escalation×1

Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.

Evidence: 2026-07-23/solarwinds-serv-u-2026-3-critical-idor-priv-esc-root · ATT&CK page ↗

Story timeline

  1. 2026-07-23SolarWinds Serv-U 2026.3 — 15 critical IDOR flaws let authenticated users escalate to root RCE on the file-transfer server (CVSS 9.1)
    trending-vulnerabilitiesSolarWinds patches 15 critical IDOR-to-root flaws in the internet-facing Serv-U managed-file-transfer server

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • documentation.solarwinds.com1 (25%)
  • heise.de1 (25%)
  • security-hub.ncsc.admin.ch1 (25%)
  • solarwinds.com1 (25%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about SolarWinds Serv-U 2026.3 IDOR/broken-access-control (priv-esc to root RCE) (1)

2026-07-23 · view entry permalink →

NOTABLECVE-2026-28304 +15NATOA1

SolarWinds Serv-U 2026.3 — 15 critical IDOR flaws let authenticated users escalate to root RCE on the file-transfer server (CVSS 9.1)

Serv-U 2026.3, released 2026-07-21, fixes 16 vulnerabilities — 15 of them critical at CVSS 9.1 — that are insecure-direct-object-reference (IDOR, CWE-639) and broken-access-control flaws in the managed-file-transfer web console rather than memory-safety bugs (SolarWinds, 2026-07-21). The consequential path is authorization: an authenticated user — in several cases needing only group- or domain-administrator scope, not full system administrator — can escalate to system administrator and achieve remote code execution as root on the underlying host, with reduced impact on Windows deployments (SolarWinds PSIRT, 2026-07-21; NCSC Switzerland, 2026-07-22). Individual flaws cover privilege escalation via configuration-path modification, arbitrary system-administrator account creation, arbitrary file read/write, account takeover through IDOR, and domain-user-group elevation to an admin group; one medium issue (CVE-2026-28315, CVSS 6.2) is a stored XSS in the admin UI usable for session hijacking. All were reported through SolarWinds' Intigriti bug-bounty program and NCSC-CH records exploitation status as unknown; heise notes Serv-U's history as a target for the Cl0p affiliate in prior MOVEit-class campaigns purely as context for why file-transfer software patch-lag is a recurring high-value target class (heise online, 2026-07-22).

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root.

SolarWinds 2026-07-21

Successful exploitation allows authenticated attackers to escalate privileges to system administrator and execute arbitrary code with root privileges via network access.

NCSC Switzerland 2026-07-22
vulnerability23 Jul 04:34Zmulti-sourceOpen finding ↗