← לוח פגיעויות

CVE-2026-28313

קריטית 9.1

תיאור (מקור, אנגלית)

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary account takeover. The impact is lower in Windows deployments.

מדדים

CVSS 3.1
9.1 (CRITICAL) מקור הציון: CNA CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
EPSS — סבירות ניצול
0% (אחוזון 000) נכון ל-1/8/2026
CWE
CWE-639

מוצרים מושפעים

solarwinds: serv-u

קישורים