CVE-2026-28309
SolarWinds Serv-U has a critical broken access control flaw that lets a domain administrator create system administrator accounts. This can give attackers full control over the Serv-U server. The vulnerability is rated CVSS 9.1.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
SolarWinds Serv-U (any version), especially non‑Windows deployments.
Real-world impact
An attacker who is a domain administrator can create a system administrator account, giving them complete control over the Serv‑U server and all its data.
Why this severity
The CVSS score is high because the flaw allows an attacker with domain administrator privileges to elevate to system administrator with low effort and no user interaction, granting full control over the system.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Jul 21, 2026 · 11d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 8d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- documentation.solarwinds.com/en/success_center/servu/con…release notesvendor advisory
- https//www.solarwinds.com/trust-c…vendor advisory