A critical access-control flaw in SolarWinds Serv-U lets a domain user group be elevated into an administrator group, earning a CVSS 3.1 base score of 9.1.
What Is It
CVE-2026-28307 is a privilege escalation vulnerability in SolarWinds Serv-U. According to SolarWinds' PSIRT advisory, the flaw allows a domain user group to be elevated into an administrator group. It is classified as an improper access control weakness (CWE-284). The impact is lower in Windows deployments.
Why It Matters
The vulnerability carries a CVSS 3.1 base score of 9.1 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H. It is remotely reachable over the network with low attack complexity and no user interaction, and it requires only existing (high) privileges to trigger. Because the scope is changed, a successful attack crosses a security boundary; an already-authenticated domain group can escalate into administrator-level control, with high impact to confidentiality, integrity, and availability. There is no KEV entry supplied for this CVE, so active exploitation is not confirmed at this time.
What's Vulnerable
The affected product is SolarWinds Serv-U. Per the vendor data, versions 15.5.4 HF1 and below are affected; other versions default to unaffected.
Patch Status
SolarWinds has published a security advisory and release notes referencing the fix. Administrators running Serv-U 15.5.4 HF1 or earlier should consult the SolarWinds Serv-U 2026-3 release notes and the CVE-2026-28307 security advisory to obtain and apply the fixed release. No supplied KEV-mandated remediation deadline accompanies this record.
Sources
- SolarWinds Serv-U 2026-3 Release Notes; https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm
- SolarWinds Security Advisory CVE-2026-28307; https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28307
- NVD, CVE-2026-28307, https://nvd.nist.gov/vuln/detail/CVE-2026-28307