CVE-2026-28307 PUBLISHED

SolarWinds Serv-U Privilege Escalation Vulnerability

Assigner: SolarWinds
Reserved: 26.02.2026 Published: 21.07.2026 Updated: 21.07.2026

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator group. The impact is lower in Windows deployments.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 9.1

Serv-U Linux

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
CVSS Score: 4.7

Serv-U Windows

Product Status

Vendor SolarWinds
Product Serv-U
Versions Default: unaffected
  • Version 15.5.4 HF1 and below is affected

Solutions

SolarWinds recommends customers to upgrade to Serv-U version 2026.3 as soon as is practical.

Credits

  • Intigriti Bug Bounty Program finder

References

Problem Types

  • CWE-284 Improper Access Control CWE

Impacts

  • CAPEC-233 Privilege Escalation