Privilege Escalation Vulnerability in SolarWinds Serv-U
CVE-2026-28306

4.7MEDIUM

Key Information:

Vendor

Solarwinds

Status
Vendor
CVE Published:
21 July 2026

What is CVE-2026-28306?

SolarWinds Serv-U contains a privilege escalation vulnerability that enables a domain administrator to gain unauthorized system administrator access. This vulnerability poses a significant risk, particularly in environments where sensitive data and administrative controls are in place. While the impact is notably decreased in Windows installations, administrators are strongly advised to assess their systems and apply necessary mitigations to safeguard against potential exploitation. For detailed information and updates, refer to the vendor advisory and release notes.

Affected Version(s)

Serv-U 15.5.4 HF1 and below

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Intigriti Bug Bounty Program
.