Skip to content
SolarWindsCVE-2026-28321

SolarWinds Serv-U: improper access control

Critical9.1CVE-2026-28321 · Published Jul 21, 2026 · updated Jul 24, 2026

SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate privileges and execute code as root. A domain administrator access is required, and the impact is lower in Windows installations.

SolarWinds advisory

Affected versions

PackageAffectedFixed in
Serv-U
Product
<= 15.5.4 HF1 and belowNo fix yet
Details and references

More SolarWinds advisories

All SolarWinds
Advisory
SolarWinds Serv-U: insecure direct object reference
Critical9.1Jul 21
SolarWinds Serv-U: privilege escalation
Critical9.1Jul 21
SolarWinds Serv-U: insecure direct object reference
Critical9.1Jul 21
SolarWinds Serv-U: insecure direct object reference
Critical9.1Jul 21
SolarWinds Serv-U: cross-site scripting
Medium6.2Jul 21
SolarWinds Serv-U: insecure direct object reference
Critical9.1Jul 21

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.