CVE-2026-28316
SolarWinds Serv‑U has an insecure direct object reference that lets a domain administrator gain root‑level command execution. The flaw can be exploited only by users with domain admin rights and is less severe on Windows installations.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
SolarWinds Serv‑U (all versions, as no specific CPEs are listed).
Real-world impact
An attacker who can log in as a domain administrator could run arbitrary commands with root privileges, giving them full control over the affected system.
Why this severity
The CVSS score of 9.1 reflects the combination of a low attack complexity, the need for high privileges, and the complete compromise of confidentiality, integrity, and availability that the vulnerability can cause.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Jul 21, 2026 · 11d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 8d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- documentation.solarwinds.com/en/success_center/servu/con…release notesvendor advisory
- solarwinds.com/trust-center/security-advis…vendor advisory