CVE-2026-28315

medium

Description

SolarWinds Serv-U was found to be affected by a stored cross-site scripting vulnerability that could lead to session hijacking or information disclosure from an administrator account.

References

https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28315

https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm

Details

Source: Mitre, NVD

Published: 2026-07-21

Updated: 2026-07-21

Risk Information

CVSS v2

Base Score: 6.1

Vector: CVSS2#AV:N/AC:L/Au:M/C:C/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 6.2

Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N

Severity: Medium

EPSS

EPSS: 0.00283