SYS::ONLINE
Wasteland.
Briefs1406
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-28309 2026-07-21

SolarWinds Serv-U Broken Access Control Flaw Lets Domain Admins Escalate to System Admin (CVE-2026-28309)

"A critical broken access control vulnerability in SolarWinds Serv-U allows a domain administrator to create system administrator accounts, earning a CVSS score of 9.1."

A critical broken access control vulnerability in SolarWinds Serv-U allows a domain administrator to create system administrator accounts, earning a CVSS score of 9.1.

What Is It

CVE-2026-28309 is a broken access control weakness (CWE-862, Missing Authorization) in SolarWinds Serv-U. According to the vendor, the flaw allows a domain administrator to create system administrator accounts—an escalation beyond the privileges that role should hold. It carries a CVSS 3.1 base score of 9.1 (CRITICAL), with the vector AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H. The network attack vector, low complexity, and changed scope reflect how an authenticated actor with elevated-but-limited privileges can cross a trust boundary to gain full system administration.

Why It Matters

Serv-U is a managed file transfer server, and system administrator access grants complete control over the deployment—its confidentiality, integrity, and availability are all rated HIGH. Because the scope is CHANGED, exploitation impacts components beyond the initially vulnerable one. The vendor notes the impact is lower in Windows deployments, implying Linux installations are more severely affected. Attack requires HIGH privileges (a domain administrator account), which limits the pool of potential attackers but still represents a meaningful escalation path in environments where domain admin does not equate to full server control.

What's Vulnerable

The affected product is SolarWinds Serv-U, version 15.5.4 HF1 and below, across both Windows and Linux platforms. Per the vendor, the practical impact is lower on Windows deployments than on Linux.

Patch Status

No CISA KEV entry accompanies this CVE, so there is no confirmed active exploitation and no federal remediation deadline at this time. The NVD record is currently Undergoing Analysis. SolarWinds documents remediation in its 2026-3 release notes and security advisory; administrators running 15.5.4 HF1 or earlier should consult those references and upgrade to the fixed release.

Sources