Description
SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system administrator and allow code execution as root. The impact is lower in Windows deployments.
Published: 2026-07-21
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SolarWinds Serv-U has a privilege escalation flaw that allows an attacker to elevate a group’s permissions to system administrator, thereby enabling code execution with root privileges. The vulnerability is less damaging in Windows deployments, but the core issue remains the same. The flaw permits elevation of privileges for groups that should not have administrative access, leading to full control over the server.

Affected Systems

The affected product is SolarWinds, but the vendor recommends upgrading to Serv-U version 2026.3 as soon as possible to address the issue.

Risk and Exploitability

The CVSS score of 4.7 indicates a moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not currently included in the CISA KEV catalog, reducing the immediate threat level. The most likely attack vector is an attacker who already has access to the Serv-U server, such as a user with limited group rights, who can manipulate group memberships to gain higher privileges. Once the group is elevated, the attacker can execute arbitrary code as root.

Generated by OpenCVE AI on July 30, 2026 at 17:16 UTC.

Remediation

Vendor Solution

SolarWinds recommends customers upgrade to Serv-U version 2026.3 as soon as is practical.


OpenCVE Recommended Actions

  • Upgrade to Serv-U version 2026.3 or later
  • Review and tighten group permissions to ensure no unnecessary groups have system administrator rights
  • Restrict access to the Serv-U administration interface and enforce least‑privilege principles

Generated by OpenCVE AI on July 30, 2026 at 17:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Solarwinds
Solarwinds serv-u
Vendors & Products Solarwinds
Solarwinds serv-u

Tue, 21 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Description SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system administrator and allow code execution as root. The impact is lower in Windows deployments.
Title SolarWinds Serv-U Privilege Escalation Vulnerability
Weaknesses CWE-285
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Solarwinds Serv-u
cve-icon MITRE

Status: PUBLISHED

Assigner: SolarWinds

Published:

Updated: 2026-07-24T03:55:43.714Z

Reserved: 2026-02-26T14:28:17.157Z

Link: CVE-2026-28312

cve-icon Vulnrichment

Updated: 2026-07-22T18:55:49.850Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T17:30:17Z

Weaknesses