Junglewise Threat Intelligence

CVE-2026-28302: SolarWinds Serv-U IDOR privilege escalation in group management

CVE-2026-28302 · Severity: critical · CVSS 9.1 · Published 2026-07-21

Technologies: SolarWinds Serv-U. Vendors: SolarWinds.

Executive brief

SolarWinds Serv-U, a managed file transfer and FTP server, is affected by a security flaw that allows an attacker to gain full control over the system. By exploiting an authorization bypass, a user with group administrator privileges can elevate their access to execute commands as the root user. This could lead to a complete compromise of the server, including the theft or deletion of sensitive files and disruption of business operations.

Technical details

SolarWinds Serv-U (version 15.5.4 HF1 and below) contains an Insecure Direct Object Reference (IDOR) vulnerability, classified as CWE-639. The flaw allows an attacker with existing group administrator privileges to bypass authorization checks by manipulating user-controlled keys. Successful exploitation enables the attacker to escalate privileges and achieve remote code execution with root/system-level authority. While the vulnerability is network-reachable, it requires high privileges (PR:H) to execute. The impact is noted to be lower on Windows deployments compared to Linux. SolarWinds has addressed this in version 2026.3.

Affected products

  • SolarWinds Serv-U 15.5.4 HF1 and below

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats