A critical insecure direct object reference flaw in SolarWinds Serv-U lets an authenticated group administrator escalate privileges and execute code as root on Linux deployments.
What Is It
CVE-2026-28302 is an insecure direct object reference (IDOR) vulnerability in SolarWinds Serv-U, classified under CWE-639. According to SolarWinds, the flaw can lead to privilege escalation and remote code execution as root. Exploitation requires group administrator access to the affected system. The vulnerability carries a CVSS 3.1 base score of 9.1 (Critical), with the vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H, network-reachable, low attack complexity, requiring high privileges, no user interaction, and a changed scope with high confidentiality, integrity, and availability impact.
Why It Matters
The vulnerability results in full root-level remote code execution, giving an attacker complete control over the underlying host. Because the scope is "changed," a compromise extends beyond the vulnerable component itself. SolarWinds notes that the impact is lower in Windows deployments, making Linux installations the primary concern. While attacker prerequisites include group administrator access, the combination of a network attack vector and root-level code execution places this at the top of the severity scale.
What's Vulnerable
The affected product is SolarWinds Serv-U, version 15.5.4 HF1 and below, across both Windows and Linux platforms. Per the vendor advisory, the impact is lower in Windows deployments; Linux systems face the full root-level RCE risk.
Patch Status
The vulnerability was published on 2026-07-21 and its NVD status is "Awaiting Analysis." No CISA KEV entry was supplied, so there is no confirmation of active exploitation at this time. SolarWinds has published a security advisory and release notes (referenced below); organizations running Serv-U 15.5.4 HF1 or earlier should consult the vendor advisory and upgrade to a fixed release.