External risk intelligence

SolarWinds Serv-U Insecure Direct Object Reference Leads to Remote Code Execution.

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-28305

SolarWinds Serv-U is typically deployed as a public-facing file transfer gateway or server intended for external user access, making its management and service interfaces commonly reachable from the internet, despite the requirement for administrative credentials to exploit this specific vulnerability.

Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical security vulnerability in SolarWinds Serv-U software that could allow unauthorized remote code execution. While exploitation requires administrative access, the nature of the vulnerability means we need to confirm if this software is deployed within our environment and if it's exposed to potential risks.

  • Insecure software allows remote control.
  • Critical flaw requires admin access.
  • Verify usage and exposure.

Attack Path

How an attacker could exploit the issue

An attacker with administrative access to SolarWinds Serv-U could exploit this vulnerability by leveraging their existing privileges to access restricted user data. This could allow them to execute arbitrary code with root privileges, potentially leading to full system compromise, although the impact is lessened on Windows systems.

  • Requires domain account with admin privileges.
  • Triggers when unauthorized data access occurs.
  • Risk of remote code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker with administrative privileges on a SolarWinds Serv-U domain account to execute arbitrary code with root privileges on the server, provided they have read and write access to the home directory. The potential impact is reduced in Windows environments.

  • Server code execution.
  • Exploits administrative account.
  • Potentially full system compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts SolarWinds Serv-U, likely managed by application owners or infrastructure teams responsible for its deployment and maintenance. The first practical step is to identify all Serv-U instances, assess their exposure and criticality, and determine the accountable owner for remediation planning.

  • Application owners should lead remediation efforts.
  • Verify Serv-U instance reachability and criticality.
  • Plan remediation based on assessed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is SolarWinds Serv-U and why is it used?

SolarWinds Serv-U is a managed file transfer software used to securely share, exchange, and transfer files across an organization. It often serves as a centralized gateway for users to upload or download data, making it a critical component for businesses that need to move sensitive information between internal systems and external partners or clients.

What does CVE-2026-28305 mean by an IDOR vulnerability?

An Insecure Direct Object Reference (IDOR) is a type of access control weakness (CWE-639). It occurs when a system provides direct access to objects, like files or directories, based on user-supplied input without verifying if the user has the proper authorization to see or modify those specific items. In this case, the flaw allows an attacker to manipulate these references to execute unauthorized code.

How is this vulnerability triggered?

An attacker needs a domain account with existing administrative privileges and specific read and write permissions to the home directory to trigger the flaw. Simply having access to the software is not enough; the attacker must be able to perform these authorized file operations to exploit the direct object reference. This issue does not trigger for standard users without administrative rights.

Is my instance of Serv-U at risk?

According to Halo Surface Signal, Serv-U is often deployed as a public-facing gateway intended for external access. If your server is reachable from the internet, it is considered externally exposed. While the vulnerability requires administrative credentials to exploit, internet-facing management interfaces inherently increase the risk surface compared to servers kept on an internal-only network.

Do I need to take immediate action if I run Serv-U?

Your first step is to inventory your environment to locate all running Serv-U instances. Once identified, confirm which instances are reachable from the internet versus those confined to internal segments. Collaborate with the infrastructure or application owners responsible for these assets to prioritize them for remediation and ensure they are patched according to the vendor's latest guidance.

References