CVE-2026-28314
Serv-U Managed File Transfer Server vulnerability analysis and mitigation

Overview

CVE-2026-28314 is an Insecure Direct Object Reference (IDOR) vulnerability in SolarWinds Serv-U Managed File Transfer that enables authenticated attackers to perform account takeover. It affects SolarWinds Serv-U versions 15.5.4 HF1 and below (all versions prior to 2026.3). The vulnerability was published on July 21, 2026, and a fix was released the same day in Serv-U 2026.3. It carries a CVSS v3.1 base score of 9.1 (Critical) (SolarWinds Advisory, GitHub Advisory). The vulnerability was discovered through the Intigriti Bug Bounty Program and is part of a broader batch of 15 critical CVEs addressed in the Serv-U 2026.3 release (Serv-U Release Notes).

Technical details

The vulnerability is classified as CWE-639 (Authorization Bypass Through User-Controlled Key), meaning the application fails to properly validate that a user-controlled key or identifier used to reference an object actually belongs to the requesting user (GitHub Advisory). An authenticated attacker with high privileges can manipulate object reference keys in requests to access or modify account data belonging to other users, ultimately achieving account takeover. The attack vector is network-based, requires no user interaction, and has low attack complexity once the attacker is authenticated. The impact is noted to be lower on Windows deployments, suggesting the most severe consequences (potentially root-level access) are more pronounced on Linux/Unix systems (SolarWinds Advisory).

Impact

Successful exploitation allows an authenticated high-privilege user to take over other user accounts within the Serv-U platform, gaining the same level of access as the compromised account — including full confidentiality, integrity, and availability impact (all rated High). Because the scope is marked as Changed in the CVSS vector, the vulnerability can affect resources beyond the initially compromised component, potentially enabling lateral movement within the file transfer environment or access to sensitive files managed by Serv-U. The impact is reduced on Windows deployments but remains critical on Linux/Unix systems where privilege escalation to root may be achievable (SolarWinds Advisory, GitHub Advisory).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.445%, placing it in the 37th percentile for exploitation likelihood within 30 days. The NVD SSVC assessment classifies exploitation as "none" and notes the attack is not automatable, as it requires authenticated high-privilege access. CVE-2026-28314 is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection signatures are available via Nessus (plugin 328845) and Qualys (detections 388010, 520222) (Feedly).

Mitigation and workarounds

SolarWinds has released a patch in Serv-U version 2026.3, which addresses CVE-2026-28314 along with 14 other critical vulnerabilities. All users running Serv-U 15.5.4 HF1 or earlier should upgrade to version 2026.3 immediately (SolarWinds Advisory, Serv-U Release Notes). As interim measures, administrators should restrict high-privilege account access to only necessary personnel, review Serv-U access logs for unauthorized account access or privilege escalation attempts, and monitor for anomalous cross-account activity. No vendor-provided configuration workaround is documented; upgrading is the only confirmed remediation.

Community reactions

The disclosure of 15 critical vulnerabilities in SolarWinds Serv-U 2026.3 attracted notable media coverage, with outlets including Heise, GBHackers, CyberPress, and Cybersecurity News reporting on the batch release (Heise, GBHackers). Security community commentary on platforms such as Bluesky and threat intelligence aggregators highlighted the severity of the combined CVE batch, with some coverage framing the release as a "crisis" given the potential for root-level remote code execution across multiple CVEs (UnderCodeNews). SolarWinds credited the Intigriti Bug Bounty Program for responsible disclosure of CVE-2026-28314 and the majority of the other critical issues in this release (Serv-U Release Notes).

Additional resources


SourceThis report was generated using AI

Related Serv-U Managed File Transfer Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-28321CRITICAL9.1
  • Serv-U Managed File Transfer Server logoServ-U Managed File Transfer Server
  • cpe:2.3:a:solarwinds:serv-u
NoYesJul 21, 2026
CVE-2026-28317CRITICAL9.1
  • Serv-U Managed File Transfer Server logoServ-U Managed File Transfer Server
  • cpe:2.3:a:solarwinds:serv-u
NoYesJul 21, 2026
CVE-2026-28316CRITICAL9.1
  • Serv-U Managed File Transfer Server logoServ-U Managed File Transfer Server
  • cpe:2.3:a:solarwinds:serv-u
NoYesJul 21, 2026
CVE-2026-28314CRITICAL9.1
  • Serv-U Managed File Transfer Server logoServ-U Managed File Transfer Server
  • cpe:2.3:a:solarwinds:serv-u
NoYesJul 21, 2026
CVE-2026-28315MEDIUM6.2
  • Serv-U Managed File Transfer Server logoServ-U Managed File Transfer Server
  • cpe:2.3:a:solarwinds:serv-u
NoYesJul 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management