A critical privilege escalation vulnerability in SolarWinds Serv-U lets a domain administrator elevate to system administrator, earning a CVSS score of 9.1.
What Is It
CVE-2026-28306 is a privilege escalation vulnerability in SolarWinds Serv-U. According to the vendor advisory, the flaw allows a domain administrator to elevate their privileges to a system administrator. SolarWinds notes that the impact is lower in Windows deployments. The weakness is classified under CWE-284 (Improper Access Control).
The record carries a CVSS 3.1 base score of 9.1 (CRITICAL), with the vector AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H. This reflects a network attack vector, low attack complexity, high privileges required, no user interaction, a changed scope, and high confidentiality, integrity, and availability impact.
Why It Matters
The scope-changed rating and full triple-high impact (confidentiality, integrity, availability) mean a successful escalation extends control beyond the initially compromised account. An attacker who already holds domain administrator access can reach system administrator level, consolidating control over the affected Serv-U deployment. While privileges required are high, the network attack vector and low complexity make exploitation straightforward for an actor who has that starting foothold.
Note: There is no CISA KEV entry accompanying this record, so active exploitation is not confirmed in the supplied source material.
What's Vulnerable
- Vendor: SolarWinds
- Product: Serv-U
- Affected versions: 15.5.4 HF1 and below
All other versions are listed with a default status of unaffected in the supplied data.
Patch Status
The supplied source material references the SolarWinds Serv-U 2026-3 release notes and the vendor security advisory for CVE-2026-28306 (linked below), indicating a fixed release beyond the affected 15.5.4 HF1 line. No CISA-mandated required action is present in the supplied data. Administrators running Serv-U 15.5.4 HF1 or earlier should consult the vendor advisory and release notes to upgrade.