Junglewise Threat Intelligence

CVE-2026-28321: SolarWinds Serv-U broken access control privilege escalation

CVE-2026-28321 · Severity: critical · CVSS 9.1 · Published 2026-07-21

Technologies: SolarWinds Serv-U. Vendors: SolarWinds.

Executive brief

SolarWinds Serv-U, a managed file transfer server, is affected by a security flaw that allows unauthorized access to the underlying file system. An attacker with domain administrator privileges can read or modify any file on the server, potentially leading to a full takeover of the system and execution of malicious code with root-level permissions. While the risk is present on all platforms, the impact is reported to be lower for installations running on Windows compared to Linux.

Technical details

A broken access control vulnerability (CWE-284) exists in SolarWinds Serv-U versions 15.5.4 HF1 and earlier. The flaw allows an authenticated attacker with domain administrator privileges to perform arbitrary file read and write operations on the host operating system. By leveraging these filesystem capabilities, an attacker can escalate privileges to achieve remote code execution as the root user. The vulnerability is exploitable over the network without user interaction, though it requires high administrative privileges as a precondition. The issue is addressed in Serv-U version 2026.3.

Affected products

  • SolarWinds Serv-U 15.5.4 HF1 and below

Timeline

  • 2026-07-21: advisory: Initial advisory published by SolarWinds
  • 2026-07-21: patched: Fixed in Serv-U version 2026.3

References

Related threats