VDB
GCVE-110-NCSC-2026-265
GCVE-110-NCSC-2026-265
Advisory PublishedCVSS 9.1/10
SolarWinds Serv-U contains an IDOR vulnerability enabling privilege escalation to system administrator with root command execution, requiring a domain account with admin access, with reduced impact on Windows deployments.
Weaknesses (CWE)
CWE-639Authorization Bypass Through User-Controlled KeyCWE-862Missing AuthorizationCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Risk Scores
CVSS 3.1
9.1/10
Critical · CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| SolarWinds | vers:unknown/* | — | — |
Browse GCVE Records
67,521 records in the GCVE database · Updated August 12, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.