Ce mail provient de l'extérieur, restons vigilants ===================================================================== CERT-Renater Note d'Information No. 2026/VULN779 _____________________________________________________________________ DATE : 24/07/2026 HARDWARE PLATFORM(S): / OPERATING SYSTEM(S): Systems running SolarWinds Serv-U versions prior to 2026.3. ===================================================================== https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28304 https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28309 https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28310 https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28314 https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28313 https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28315 https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28312 https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28316 https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28311 https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28302 https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28321 https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28308 https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28306 _____________________________________________________________________ SolarWinds Serv-U Remote Code Execution Vulnerability (CVE-2026-28304) Summary SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary execution of code remotely as root. The impact is lower in Windows deployments. Affected Products SolarWinds Serv-U 15.5.4 HF1 and below Fixed Software Release SolarWinds Serv-U 2026.3 Acknowledgments Intigriti Bug Bounty Program Advisory Details Severity 9.1 Critical Advisory ID CVE-2026-28304 First Published 07/21/2026 Fixed Version SolarWinds Serv-U 2026.3 CVSS Score CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H _____________________________________________________________________ SolarWinds Serv-U Broken Access Control Vulnerability (CVE-2026-28309) Summary SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. The impact is lower in Windows deployments. Affected Products SolarWinds Serv-U 15.5.4 HF1 and below Fixed Software Release SolarWinds Serv-U 2026.3 Acknowledgments Intigriti Bug Bounty Program Advisory Details Severity 9.1 Critical Advisory ID CVE-2026-28309 First Published 07/21/2026 Fixed Version SolarWinds Serv-U 2026.3 CVSS Score CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H _____________________________________________________________________ SolarWinds Serv-U Privilege Escalation Vulnerability (CVE-2026-28310) Summary SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate their user type to that of a system administrator. The impact is lower in Windows deployments. Affected Products SolarWinds Serv-U 15.5.4 HF1 and below Fixed Software Release SolarWinds Serv-U 2026.3 Acknowledgments Intigriti Bug Bounty Program Advisory Details Severity 9.1. Critical Advisory ID CVE-2026-28310 First Published 07/21/2026 Fixed Version SolarWinds Serv-U 2026.3 CVSS Score CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H _____________________________________________________________________ SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability (CVE-2026-28314) Summary SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. User authentication is required. The impact is lower in Windows deployments. Affected Products SolarWinds Serv-U 15.5.4 HF1 and below Fixed Software Release SolarWinds Serv-U 2026.3 Acknowledgments Intigriti Bug Bounty Program Advisory Details Severity 9.1. Critical Advisory ID CVE-2026-28314 First Published 07/21/2026 Fixed Version SolarWinds Serv-U 2026.3 CVSS Score CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H _____________________________________________________________________ SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability (CVE-2026-28313) Summary SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary account takeover. The impact is lower in Windows deployments. Affected Products SolarWinds Serv-U 15.5.4 HF1 and below Fixed Software Release SolarWinds Serv-U 2026.3 Acknowledgments Intigriti Bug Bounty Program Advisory Details Severity 9.1. Critical Advisory ID CVE-2026-28313 First Published 07/21/2026 Fixed Version SolarWinds Serv-U 2026.3 CVSS Score CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H _____________________________________________________________________ SolarWinds Serv-U Authenticated Stored Cross-site Scripting (XSS) Vulnerability (CVE-2026-28315) Summary SolarWinds Serv-U was found to be affected by a stored cross-site scripting vulnerability that could lead to session hijacking or information disclosure from an administrator account. Affected Products SolarWinds Serv-U 15.5.4 HF1 and below Fixed Software Release SolarWinds Serv-U 2026.3 Advisory Details Severity 6.2 Medium Advisory ID CVE-2026-28315 First Published 07/21/2026 Fixed Version SolarWinds Serv-U 2026.3 CVSS Score CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N ____________________________________________________________ SolarWinds Serv-U Privilege Escalation Vulnerability (CVE-2026-28312) Summary SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system administrator and allow code execution as root. The impact is lower in Windows deployments. Affected Products SolarWinds Serv-U 15.5.4 HF1 and below Fixed Software Release SolarWinds Serv-U 2026.3 Acknowledgments Intigriti Bug Bounty Program Advisory Details Severity 9.1. Critical Advisory ID CVE-2026-28312 First Published 07/21/2026 Fixed Version SolarWinds Serv-U 2026.3 CVSS Score CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H _____________________________________________________________________ SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability (CVE-2026-28316) Summary SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability to execute commands as the root user. This issue requires a domain account with administrator access. The impact is lower in Windows deployments. Affected Products SolarWinds Serv-U 15.5.4 HF1 and below Fixed Software Release SolarWinds Serv-U 2026.3 Acknowledgments Intigriti Bug Bounty Program Advisory Details Severity 9.1 Critical Advisory ID CVE-2026-28316 First Published 07/21/2026 Fixed Version SolarWinds Serv-U 2026.3 CVSS Score CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H _____________________________________________________________________ SolarWinds Serv-U Remote Code Execution Vulnerability (CVE-2026-28311) Summary SolarWinds Serv-U is affected by a remote code execution vulnerability that allows a domain administrator to modify how the application behaves, which can lead to remote code execution. The impact is lower in Windows deployments. Affected Products SolarWinds Serv-U 15.5.4 HF1 and below Fixed Software Release SolarWinds Serv-U 2026.3 Acknowledgments Intigriti Bug Bounty Program Advisory Details Severity 9.1 Critical Advisory ID CVE-2026-28311 First Published 07/21/2026 Fixed Version SolarWinds Serv-U 2026.3 CVSS Score CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H _____________________________________________________________________ SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability (CVE-2026-28302) Summary SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root. This issue requires group administrator access. The impact is lower in Windows deployments. Affected Products SolarWinds Serv-U 15.5.4 HF1 and below Fixed Software Release SolarWinds Serv-U 2026.3 Acknowledgments Intigriti Bug Bounty Program Advisory Details Severity 9.1. Critical Advisory ID CVE-2026-28302 First Published 07/21/2026 Fixed Version SolarWinds Serv-U 2026.3 CVSS Score CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H _____________________________________________________________________ SolarWinds Serv-U Broken Access Control Vulnerability (CVE-2026-28321) Summary SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate privileges and execute code as root. A domain administrator access is required, and the impact is lower in Windows installations. Affected Products SolarWinds Serv-U 15.5.4 HF1 and below Fixed Software Release SolarWinds Serv-U 2026.3 Acknowledgments Intigriti Bug Bounty Program Advisory Details Severity 9.1 Critical Advisory ID CVE-2026-28321 First Published 07/21/2026 Fixed Version SolarWinds Serv-U 2026.3 CVSS Score CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H _____________________________________________________________________ SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability (CVE-2026-28308) Summary SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrator access is required. The impact is lower in Windows deployments. Affected Products SolarWinds Serv-U 15.5.4 HF1 and below Fixed Software Release SolarWinds Serv-U 2026.3 Acknowledgments Intigriti Bug Bounty Program Advisory Details Severity 9.1. Critical Advisory ID CVE-2026-28308 First Published 07/21/2026 Fixed Version SolarWinds Serv-U 2026.3 CVSS Score CVSS:3.1 /AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H _____________________________________________________________________ SolarWinds Serv-U Privilege Escalation Vulnerability (CVE-2026-28306) Summary SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system administrator. The impact is lower in Windows deployments. Affected Products SolarWinds Serv-U 15.5.4 HF1 and below Fixed Software Release SolarWinds Serv-U 2026.3 Acknowledgments Intigriti Bug Bounty Program Advisory Details Severity 9.1 Critical Advisory ID CVE-2026-28306 First Published 07/21/2026 Fixed Version SolarWinds Serv-U 2026.3 CVSS Score CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H ========================================================= + CERT-RENATER | tel : 01-53-94-20-44 + + 23/25 Rue Daviel | fax : 01-53-94-20-41 + + 75013 Paris | email:cert@support.renater.fr + =========================================================