CVE-2026-28321 PUBLISHED

SolarWinds Serv-U Broken Access Control Vulnerability

Assigner: SolarWinds
Reserved: 26.02.2026 Published: 21.07.2026 Updated: 21.07.2026

SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate privileges and execute code as root. A domain administrator access is required, and the impact is lower in Windows installations.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 9.1

Serv-U Linux

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
CVSS Score: 4.7

Serv-U Windows

Product Status

Vendor SolarWinds
Product Serv-U
Versions Default: unaffected
  • Version 15.5.4 HF1 and below is affected

Solutions

SolarWinds recommends customers upgrade to Serv-U version 2026.3 as soon as is practical.

Credits

  • Intigriti Bug Bounty Program finder

References

Problem Types

  • CWE-284 Improper Access Control CWE

Impacts

  • CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs
  • CAPEC-126 Path Traversal
  • CAPEC-242 Code Injection