Description
SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate privileges and execute code as root. A domain administrator access is required, and the impact is lower in Windows installations.
Published: 2026-07-21
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SolarWinds Serv‑U suffers a broken access control flaw that allows an attacker with domain administrator rights to read and write arbitrary files on the server. By exploiting this vulnerability the attacker can elevate privileges to the root level and subsequently execute arbitrary code. The flaw is identified as CWE‑284 and has a CVSS score of 4.7. Although the impact is mitigated on Windows installations, the issue remains significant on non‑Windows systems.

Affected Systems

Serv‑U versions prior to 2026.3 are affected. All customers running these versions should upgrade to Serv‑U 2026.3 or later as soon as practicable, following the vendor’s recommendation.

Risk and Exploitability

The CVSS score of 4.7 indicates moderate severity, and an EPSS score of less than 1% reflects a very low probability of exploitation in production environments. The vulnerability is not listed in CISA KEV. Attackers require domain administrator access, so the risk is constrained by access control policies but, if achieved, can lead to full system compromise.

Generated by OpenCVE AI on July 27, 2026 at 15:42 UTC.

Remediation

Vendor Solution

SolarWinds recommends customers upgrade to Serv-U version 2026.3 as soon as is practical.


OpenCVE Recommended Actions

  • Apply the Serv‑U 2026.3 update to all affected installations immediately.
  • Revoke unnecessary domain administrator rights from users to minimize the attack surface.
  • Enforce strict file‑system permissions on Serv‑U directories and configuration files to prevent arbitrary read/write operations.

Generated by OpenCVE AI on July 27, 2026 at 15:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Solarwinds
Solarwinds serv-u
Vendors & Products Solarwinds
Solarwinds serv-u

Tue, 21 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Description SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate privileges and execute code as root. A domain administrator access is required, and the impact is lower in Windows installations.
Title SolarWinds Serv-U Broken Access Control Vulnerability
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Solarwinds Serv-u
cve-icon MITRE

Status: PUBLISHED

Assigner: SolarWinds

Published:

Updated: 2026-07-24T03:55:48.019Z

Reserved: 2026-02-26T14:46:41.520Z

Link: CVE-2026-28321

cve-icon Vulnrichment

Updated: 2026-07-21T17:28:56.766Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-27T15:45:03Z

Weaknesses