Junglewise Threat Intelligence

CVE-2026-28307: SolarWinds Serv-U privilege escalation in domain user groups

CVE-2026-28307 · Severity: critical · CVSS 9.1 · Published 2026-07-21

Technologies: SolarWinds Serv-U. Vendors: SolarWinds.

Executive brief

SolarWinds Serv-U, a managed file transfer and FTP server, is affected by a security flaw that allows certain users to gain unauthorized administrative control. An attacker with existing high-level permissions could exploit this to elevate a standard domain user group into a full administrator group. This could lead to a complete takeover of the file transfer service and unauthorized access to sensitive data stored on the server.

Technical details

A privilege escalation vulnerability exists in SolarWinds Serv-U due to improper access control (CWE-284). The flaw allows an attacker with high-privileged credentials to elevate a domain user group to an administrator group, potentially leading to a full compromise of the Serv-U instance. The attack vector is network-based and requires high privileges but no user interaction. While the vulnerability affects multiple platforms, the vendor notes that the impact is lower in Windows-based deployments. The issue is resolved in Serv-U version 2026.3.

Affected products

  • SolarWinds Serv-U 15.5.4 HF1 and below

Timeline

  • 2026-07-21: advisory: Initial advisory published by SolarWinds
  • 2026-07-21: patched: Fixed in Serv-U 2026.3

References

Related threats