Broken Access Control in SolarWinds Serv-U Affects Domain Administrators
CVE-2026-28309
4.7MEDIUM
What is CVE-2026-28309?
SolarWinds Serv-U contains a vulnerability where improper access control mechanisms enable domain administrators to create unauthorized system administrator accounts. This issue is more pronounced in non-Windows environments, potentially granting elevated privileges to malicious users. Organizations using affected versions should review their security configurations and apply necessary updates to mitigate risks.
Affected Version(s)
Serv-U Windows 15.5.4 HF1 and below