Description
SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate their user type to that of a system administrator. The impact is lower in Windows deployments.
Published: 2026-07-21
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SolarWinds Serv-U is vulnerable to a privilege escalation flaw that permits an account with domain administrator privileges to elevate to a system administrator role. The weakness, identified as CWE-862 (Insufficient Privilege Management), enables a local attacker to increase their authority over the Serv-U installation, potentially giving full control over server configuration and sensitive data. The effect is less severe in Windows-based deployments, according to the vendor’s description.

Affected Systems

The vulnerability affects all versions of SolarWinds Serv-U that are currently in use. SolarWinds recommends applying the Serv-U 2026.3 release, which contains the fix for this issue, as an immediate remediation. Users running Windows systems should also verify that the upgraded version behaves as expected, although the impact is reported to be lower on such platforms.

Risk and Exploitability

The CVSS score of 4.7 indicates that the flaw is of moderate severity, and the EPSS score, being less than 1%, suggests a low probability of exploitation at present. It is not listed in CISA’s KE vector requires an authenticated domain administrator to trigger the escalation, implying that internal users or compromised domain credentials could be used to exploit the flaw. Because the vulnerability requires existing administrative access, an attacker would need the ability to log into the Serv-U environment, after which the privilege jump can occur without additional effort.

Generated by OpenCVE AI on July 30, 2026 at 17:16 UTC.

Remediation

Vendor Solution

SolarWinds recommends customers to upgrade to Serv-U version 2026.3 as soon as is practical.


OpenCVE Recommended Actions

  • Apply the Serv-U 2026.3 upgrade to eliminate the privilege escalation flaw
  • Restrict domain administrator privileges to only those systems that require them
  • Audit and review user accounts for unnecessary administrator rights
  • Monitor authentication logs for unexpected privilege elevation attempts

Generated by OpenCVE AI on July 30, 2026 at 17:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Solarwinds
Solarwinds serv-u
Vendors & Products Solarwinds
Solarwinds serv-u

Tue, 21 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Description SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate their user type to that of a system administrator. The impact is lower in Windows deployments.
Title SolarWinds Serv-U Privilege Escalation Vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Solarwinds Serv-u
cve-icon MITRE

Status: PUBLISHED

Assigner: SolarWinds

Published:

Updated: 2026-07-24T03:55:42.875Z

Reserved: 2026-02-26T14:28:17.157Z

Link: CVE-2026-28310

cve-icon Vulnrichment

Updated: 2026-07-22T18:53:38.772Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T17:30:17Z

Weaknesses