Junglewise Threat Intelligence

CVE-2026-28310: SolarWinds Serv-U privilege escalation in administrative interface

CVE-2026-28310 · Severity: critical · CVSS 9.1 · Published 2026-07-21

Technologies: SolarWinds Serv-U. Vendors: SolarWinds.

Executive brief

SolarWinds Serv-U, a managed file transfer server, is affected by a security flaw that allows a domain administrator to gain full system administrator privileges. This could allow an individual with limited administrative access to take complete control over the entire file transfer server and its data. The risk is particularly high for Linux-based deployments, though Windows systems are also affected.

Technical details

A privilege escalation vulnerability exists in SolarWinds Serv-U due to missing authorization (CWE-862). An attacker with domain administrator credentials can exploit this flaw over the network to elevate their privileges to a full system administrator. While the vulnerability affects both platforms, the impact is reportedly lower in Windows deployments compared to Linux. The issue is addressed in Serv-U version 2026.3.

Affected products

  • SolarWinds Serv-U 15.5.4 HF1 and below

Timeline

  • 2026-07-21: advisory: Initial advisory published by SolarWinds and NVD.
  • 2026-07-21: patched: Fix released in version 2026.3.

References

Related threats