Privilege Escalation Vulnerability in SolarWinds Serv-U
CVE-2026-28307

4.7MEDIUM

Key Information:

Vendor

Solarwinds

Status
Vendor
CVE Published:
21 July 2026

What is CVE-2026-28307?

SolarWinds Serv-U is susceptible to a privilege escalation flaw that could enable users within a domain user group to escalate their permissions to those of an administrator group. This vulnerability primarily affects deployments in environments where Serv-U is utilized, posing potential risks for user access management. The implications are notably reduced in Windows deployments, making it crucial for administrators to review user group policies and system configurations to mitigate the risk.

Affected Version(s)

Serv-U 15.5.4 HF1 and below

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Intigriti Bug Bounty Program
.