Description
SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system administrator. The impact is lower in Windows deployments.
Published: 2026-07-21
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in SolarWinds Serv‑U allows a domain administrator to elevate their privileges to a system administrator. This is a privilege escalation flaw classified as CWE‑284. The immediate impact is that an attacker with domain administrative rights could gain full system control on the affected host. The severity is moderate, and the effect is reduced in Windows deployments according to the vendor statement.

Affected Systems

SolarWinds Serv‑U instances that are not running the latest version 2026.3 are potentially affected; the advisory does not specify exact version numbers. Affected users should determine whether their installation was built before the 2026.3 release and plan an upgrade if necessary.

Risk and Exploitability

The CVSS score of 4.7 indicates moderate risk, while the EPSS score of less than 1% suggests that exploitation is unlikely at present. The flaw is not listed in the CISA KEV catalog. The likely attack path assumes the attacker already possesses domain administrator credentials, from which the exploit elevates privileges to a system administrator. The advisory does not specify a network‑based vector, implying that the exploit would require local or domain-level access and would not necessarily expose the system to external attackers.

Generated by OpenCVE AI on July 30, 2026 at 17:18 UTC.

Remediation

Vendor Solution

SolarWinds recommends customers to upgrade to Serv-U version 2026.3 as soon as is practical.


OpenCVE Recommended Actions

  • Upgrade to Serv‑U version 2026.3 as soon as is practical.
  • Restrict domain administrator privileges to the minimum necessary and remove any unnecessary admin rights.
  • Monitor system logs for signs of unauthorized privilege escalation after the upgrade.

Generated by OpenCVE AI on July 30, 2026 at 17:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Solarwinds
Solarwinds serv-u
Vendors & Products Solarwinds
Solarwinds serv-u

Tue, 21 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Description SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system administrator. The impact is lower in Windows deployments.
Title SolarWinds Serv-U Privilege Escalation Vulnerability
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Solarwinds Serv-u
cve-icon MITRE

Status: PUBLISHED

Assigner: SolarWinds

Published:

Updated: 2026-07-24T03:55:39.494Z

Reserved: 2026-02-26T14:15:09.403Z

Link: CVE-2026-28306

cve-icon Vulnrichment

Updated: 2026-07-22T18:08:53.180Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T17:30:17Z

Weaknesses