CVE-2026-28309: SolarWinds Serv-U Broken Access Control Vulnerability
SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. The impact is lower in Windows deployments.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SolarWinds Serv-Uto a version that resolves this vulnerability.Fixed in 2026.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28309?
CVE-2026-28309 has a severity score of 9.1, classifying it as critical.
What type of vulnerability is CVE-2026-28309?
CVE-2026-28309 is a broken access control vulnerability affecting SolarWinds Serv-U.
How can one exploit CVE-2026-28309?
An attacker can exploit CVE-2026-28309 by leveraging the broken access control to create unauthorized system administrator accounts.
Is the impact of CVE-2026-28309 different on Windows deployments?
Yes, the impact of CVE-2026-28309 is lower in Windows deployments.
How do I fix CVE-2026-28309?
To fix CVE-2026-28309, apply the latest security updates provided by SolarWinds for Serv-U.