Description
SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. The impact is lower in Windows deployments.
Published: 2026-07-21
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SolarWinds Serv-U is vulnerable to a broken access control flaw that allows a domain administrator to create system administrator accounts. The flaw enables users with domain admin rights to gain full control of the Serv-U application, effectively elevating their privileges. This elevated access could be used to read, modify, or delete sensitive data, deploy malicious software, or maintain persistent presence within the environment. The effect is limited to users who already hold domain administrative privileges, and the impact is reduced in Windows deployments according to the vendor's commentary.

Affected Systems

The affected product is SolarWinds Serv-U, with the vendor specifically identified as SolarWinds:Serv-U. No explicit version range is listed in the advisory, but the vendor recommends moving to Serv‑U version 2026.3 or newer as soon as practical. Users of earlier Serv‑U releases that have not applied this update remain vulnerable, and the advisory explicitly mentions a lower impact in Windows deployments.

Risk and Exploitability

The CVSS score of 4.7 places this vulnerability in the moderate range, and an EPSS score of exploitation in the wild. The flaw is not listed in the CISA KEV catalog, suggesting no known active exploits have been observed. Exploitation requires an attacker to already be a domain administrator, so the attack vector is internal and relies on legitimate domain administrative privileges. Due to the precision of the flaw in the Serv‑U code base, an attacker could create privileged accounts with little effort once inside the domain. The moderate score and low EPSS imply that the overall risk is moderate, but the potential impact on confidentiality, integrity, and availability justifies immediate remediation.

Generated by OpenCVE AI on July 30, 2026 at 17:17 UTC.

Remediation

Vendor Solution

SolarWinds recommends customers to upgrade to Serv-U version 2026.3 as soon as is practical.


OpenCVE Recommended Actions

  • Upgrade Serv‑U to version 2026.3 or later.
  • Restrict domain administrators from creating or managing system administrator accounts by adjusting group policy or application settings.
  • Remove or disable redundant local system administrator accounts that are not required for operation.

Generated by OpenCVE AI on July 30, 2026 at 17:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Solarwinds
Solarwinds serv-u
Vendors & Products Solarwinds
Solarwinds serv-u

Tue, 21 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Description SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. The impact is lower in Windows deployments.
Title SolarWinds Serv-U Broken Access Control Vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Solarwinds Serv-u
cve-icon MITRE

Status: PUBLISHED

Assigner: SolarWinds

Published:

Updated: 2026-07-24T03:55:41.996Z

Reserved: 2026-02-26T14:28:17.157Z

Link: CVE-2026-28309

cve-icon Vulnrichment

Updated: 2026-07-22T18:52:17.754Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T17:30:17Z

Weaknesses