Description
SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator group. The impact is lower in Windows deployments.
Published: 2026-07-21
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SolarWinds Serv‑U has a flaw that lets a user group that is normally granted domain permissions be elevated to the administrator group within the application. This weakness, identified as CWE‑284, allows non‑privileged users to gain administrative rights over the Serv‑U service, potentially exposing configuration data, user accounts, and files managed by the application. The description notes that in Windows deployments the impact is lower, but any elevation of privileges can compromise the system’s security posture.

Affected Systems

The vulnerability affects all installations of SolarWinds Serv‑U that run versions prior to 2026.3, as the advisory recommends upgrading to at least that release to eliminate the flaw. Users on earlier releases that rely on domain user groups for controlling service access are potential targets, regardless of the underlying operating system.

Risk and Exploitability

The CVSS score of 4.7 indicates moderate severity, while an EPSS score of less than 1% suggests a low probability of exploitation in practice. The vulnerability is not listed in the CISA KEV catalog. Attackers would likely need a legitimate domain account that is a member of a user group that can be promoted to administrators, implying a local or network-based privilege escalation scenario rather than a remote exploit. The restricted scope and low exploitation likelihood reduce overall risk, yet the potential to compromise service configuration warrants attention.

Generated by OpenCVE AI on July 30, 2026 at 17:18 UTC.

Remediation

Vendor Solution

SolarWinds recommends customers to upgrade to Serv-U version 2026.3 as soon as is practical.


OpenCVE Recommended Actions

  • Upgrade Serv-U to version 2026.3 or later to fix the flaw.
  • Revoke or reduce the domain user group’s permissions that allow promotion to the administrator group within Serv‑U.
  • Apply least‑privilege principles and audit activity logs for unusual privilege escalation attempts.

Generated by OpenCVE AI on July 30, 2026 at 17:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Solarwinds
Solarwinds serv-u
Vendors & Products Solarwinds
Solarwinds serv-u

Tue, 21 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Description SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator group. The impact is lower in Windows deployments.
Title SolarWinds Serv-U Privilege Escalation Vulnerability
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Solarwinds Serv-u
cve-icon MITRE

Status: PUBLISHED

Assigner: SolarWinds

Published:

Updated: 2026-07-24T03:55:40.379Z

Reserved: 2026-02-26T14:28:17.157Z

Link: CVE-2026-28307

cve-icon Vulnrichment

Updated: 2026-07-22T18:47:49.903Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T17:30:17Z

Weaknesses