Junglewise Threat Intelligence

CVE-2026-28306: SolarWinds Serv-U privilege escalation in domain administration

CVE-2026-28306 · Severity: critical · CVSS 9.1 · Published 2026-07-21

Technologies: SolarWinds Serv-U. Vendors: SolarWinds.

Executive brief

SolarWinds Serv-U, a managed file transfer and FTP server, is affected by a security flaw that allows certain administrative users to gain full control over the entire system. A domain administrator can exploit this vulnerability to elevate their access to system administrator status, potentially leading to unauthorized access to sensitive files and configuration settings. This issue is particularly severe in non-Windows environments, though Windows deployments are also impacted to a lesser degree.

Technical details

A privilege escalation vulnerability (CWE-284: Improper Access Control) exists in SolarWinds Serv-U versions 15.5.4 HF1 and earlier. The flaw allows an authenticated attacker with domain administrator privileges to bypass access controls and elevate their permissions to system administrator level. The attack vector is network-based and requires high privileges to initiate, but it results in a scope change (S:C) allowing full compromise of the application environment. SolarWinds has addressed this in the Serv-U 2026.3 release.

Affected products

  • SolarWinds Serv-U 15.5.4 HF1 and below

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats