A critical privilege escalation flaw in SolarWinds Serv-U can elevate a group's access to system administrator and allow code execution as root, with reduced impact on Windows deployments.
What Is It
CVE-2026-28312 is a privilege escalation vulnerability (CWE-285, Improper Authorization) in SolarWinds Serv-U. According to the vendor, the flaw elevates a group's access to system administrator and allows code execution as root. The impact is lower in Windows deployments. It carries a CVSS 3.1 base score of 9.1 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H, network-accessible, low attack complexity, but requiring high privileges and no user interaction, with a changed scope and high confidentiality, integrity, and availability impact.
Why It Matters
The vulnerability results in full compromise of the affected system: code execution as root. Because the scope is changed and all three impact metrics are rated high, a successful attack extends beyond the vulnerable component. The network attack vector and low attack complexity make exploitation straightforward for an actor who already holds the required high privileges. There is no CISA KEV entry in the supplied material, so active exploitation is not confirmed by KEV at this time. The NVD record status is "Undergoing Analysis."
What's Vulnerable
The affected product is SolarWinds Serv-U on both Windows and Linux platforms. Versions 15.5.4 HF1 and below are listed as affected. The impact is noted as lower in Windows deployments.
Patch Status
The supplied source material references the SolarWinds Serv-U 2026.3 release notes and the vendor security advisory for CVE-2026-28312. Organizations running Serv-U 15.5.4 HF1 or earlier should consult the SolarWinds advisory and release notes to identify and apply the fixed release. No separate CISA-mandated required action is present in the supplied data.
Sources
- SolarWinds Serv-U 2026.3 Release Notes; https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm
- SolarWinds Security Advisory CVE-2026-28312; https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28312
- NVD, CVE-2026-28312 (source: [email protected])