CVE-2026-28317 – SolarWinds Serv-U

CVSS 9.1 CRITICAL Critical - Same Day Deployment

“A chain of access control flaws can turn administrative privileges into full system compromise.”

This update addresses multiple vulnerabilities affecting SolarWinds Serv-U. CVE-2026-28302, CVE-2026-28304, CVE-2026-28305, CVE-2026-28306, CVE-2026-28307, CVE-2026-28308, CVE-2026-28309, CVE-2026-28310, CVE-2026-28312, CVE-2026-28313, CVE-2026-28314, CVE-2026-28316, CVE-2026-28317, and CVE-2026-28321 each have a CVSS score of 9.1, which is Critical severity. CVE-2026-28315 has a CVSS score of 6.2, which is Medium severity. No verified real-world exploitation has been reported for these vulnerabilities.

The vulnerabilities include insecure direct object reference (IDOR), broken access control, improper authorization, and privilege escalation flaws that can result in unauthorized account access, administrator privilege escalation, arbitrary file read and write, SMTP hijacking, account takeover, and, in several scenarios, execution of code as the root user. Many of the Critical vulnerabilities require an authenticated domain administrator or group administrator account, while some can elevate domain users or groups to system administrator privileges. The impact is generally lower on Windows deployments, but affected Linux and UNIX environments remain at greater risk. The update also resolves a stored cross-site scripting vulnerability that could lead to administrator session hijacking or information disclosure.

Note: CVE-2026-28311 is not included because no valid CVE record was available.

Key Details

Affected Product
Solarwinds Serv-u
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
CWE Classification
CWE-639
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.