A critical broken access control vulnerability in SolarWinds Serv-U allows a domain administrator to create system administrator accounts, earning a CVSS score of 9.1.
What Is It
CVE-2026-28309 is a broken access control weakness (CWE-862, Missing Authorization) in SolarWinds Serv-U. According to the vendor, the flaw allows a domain administrator to create system administrator accounts—an escalation beyond the privileges that role should hold. It carries a CVSS 3.1 base score of 9.1 (CRITICAL), with the vector AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H. The network attack vector, low complexity, and changed scope reflect how an authenticated actor with elevated-but-limited privileges can cross a trust boundary to gain full system administration.
Why It Matters
Serv-U is a managed file transfer server, and system administrator access grants complete control over the deployment—its confidentiality, integrity, and availability are all rated HIGH. Because the scope is CHANGED, exploitation impacts components beyond the initially vulnerable one. The vendor notes the impact is lower in Windows deployments, implying Linux installations are more severely affected. Attack requires HIGH privileges (a domain administrator account), which limits the pool of potential attackers but still represents a meaningful escalation path in environments where domain admin does not equate to full server control.
What's Vulnerable
The affected product is SolarWinds Serv-U, version 15.5.4 HF1 and below, across both Windows and Linux platforms. Per the vendor, the practical impact is lower on Windows deployments than on Linux.
Patch Status
No CISA KEV entry accompanies this CVE, so there is no confirmed active exploitation and no federal remediation deadline at this time. The NVD record is currently Undergoing Analysis. SolarWinds documents remediation in its 2026-3 release notes and security advisory; administrators running 15.5.4 HF1 or earlier should consult those references and upgrade to the fixed release.
Sources
- NVD, CVE-2026-28309: https://nvd.nist.gov/vuln/detail/CVE-2026-28309
- SolarWinds Serv-U 2026-3 Release Notes: https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm
- SolarWinds Security Advisory; CVE-2026-28309: https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28309