A critical authorization vulnerability in SolarWinds Serv-U lets a domain administrator escalate to a full system administrator, earning a CVSS score of 9.1.
What Is It
CVE-2026-28310 is a privilege escalation vulnerability in SolarWinds Serv-U. According to SolarWinds' PSIRT, the flaw allows a domain administrator to escalate their user type to that of a system administrator. It is classified as CWE-862 (Missing Authorization) and carries a CVSS 3.1 base score of 9.1 (Critical), with the vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H. The network attack vector, low complexity, changed scope, and high confidentiality, integrity, and availability impacts drive the critical rating. SolarWinds notes the impact is lower in Windows deployments.
Why It Matters
An attacker who already holds domain administrator privileges can cross a privilege boundary and gain system administrator control over the Serv-U file transfer server. The changed scope (S:C) and uniformly high impact ratings reflect that a successful escalation compromises confidentiality, integrity, and availability. Because the required privileges are high, exploitation depends on an actor first obtaining domain admin access, but the outcome is full administrative takeover of the affected service. No CISA KEV entry accompanies this record, so there is no confirmation of active exploitation in the supplied data.
What's Vulnerable
The affected product is SolarWinds Serv-U across Windows and Linux platforms. Versions 15.5.4 HF1 and below are listed as affected. The NVD record is currently in "Undergoing Analysis" status, and no affected CPEs were enumerated at time of publication. SolarWinds indicates the impact is reduced on Windows deployments relative to Linux.
Patch Status
SolarWinds has published a security advisory and release notes for the Serv-U 2026-3 release addressing this issue. Administrators running Serv-U 15.5.4 HF1 or earlier should consult the vendor release notes and advisory to upgrade to the fixed release.
Sources
- NVD, CVE-2026-28310: https://nvd.nist.gov/vuln/detail/CVE-2026-28310
- SolarWinds Serv-U 2026-3 Release Notes: https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm
- SolarWinds Security Advisory; CVE-2026-28310: https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28310