SYS::ONLINE
Wasteland.
Briefs1404
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-28306 2026-07-21

SolarWinds Serv-U Privilege Escalation Flaw Rated Critical (CVE-2026-28306)

"A critical privilege escalation vulnerability in SolarWinds Serv-U lets a domain administrator elevate to system administrator, earning a CVSS score of 9.1."

A critical privilege escalation vulnerability in SolarWinds Serv-U lets a domain administrator elevate to system administrator, earning a CVSS score of 9.1.

What Is It

CVE-2026-28306 is a privilege escalation vulnerability in SolarWinds Serv-U. According to the vendor advisory, the flaw allows a domain administrator to elevate their privileges to a system administrator. SolarWinds notes that the impact is lower in Windows deployments. The weakness is classified under CWE-284 (Improper Access Control).

The record carries a CVSS 3.1 base score of 9.1 (CRITICAL), with the vector AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H. This reflects a network attack vector, low attack complexity, high privileges required, no user interaction, a changed scope, and high confidentiality, integrity, and availability impact.

Why It Matters

The scope-changed rating and full triple-high impact (confidentiality, integrity, availability) mean a successful escalation extends control beyond the initially compromised account. An attacker who already holds domain administrator access can reach system administrator level, consolidating control over the affected Serv-U deployment. While privileges required are high, the network attack vector and low complexity make exploitation straightforward for an actor who has that starting foothold.

Note: There is no CISA KEV entry accompanying this record, so active exploitation is not confirmed in the supplied source material.

What's Vulnerable

All other versions are listed with a default status of unaffected in the supplied data.

Patch Status

The supplied source material references the SolarWinds Serv-U 2026-3 release notes and the vendor security advisory for CVE-2026-28306 (linked below), indicating a fixed release beyond the affected 15.5.4 HF1 line. No CISA-mandated required action is present in the supplied data. Administrators running Serv-U 15.5.4 HF1 or earlier should consult the vendor advisory and release notes to upgrade.

Sources