← Vulnerability feed

Vulnerability record · CVE-2026-28321 · published 21 July 2026

CVE-2026-28321: Solarwinds serv-u improper access control vulnerability

Solarwinds · Serv U

SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate privileges and execute code as root. A domain administrator access is required, and the impact is lower in Windows installations.

9.1 CVSS 3.1 Critical EPSS 0.58% · top 54.7% CWE-284 · Improper access control
9.1CVSS 3.1 base score
0.58%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
24 Jul 2026Last modified by NVD

Description

SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate privileges and execute code as root. A domain administrator access is required, and the impact is lower in Windows installations.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-28321 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-35211SolarWinds Serv-U out-of-bounds write enables remote code executionSolarWinds Serv-U Managed File Transfer and Serv-U Secure FTP for Windows before 15.2.3 HF2 contain an out-of-bounds write (CWE-787) that Microsoft d…KEVEPSS 91%analysed7.5CVE-2026-28318SolarWinds Serv-U unauthenticated POST request denial of serviceSolarWinds Serv-U crashes when it receives a specially crafted POST request using Content-Encoding: deflate, and the crash occurs without authenticat…KEVEPSS 1.9%analysed7.5CVE-2024-28995SolarWinds Serv-U path traversal allows arbitrary file readSolarWinds Serv-U contains a path traversal flaw (CWE-22) that lets an unauthenticated remote attacker read sensitive files from the host. The vulner…KEVEPSS 100%analysed5.3CVE-2021-35247SolarWinds Serv-U web login LDAP input validation flawThe Serv-U web login screen passed characters to LDAP authentication without sufficient sanitization. SolarWinds updated the input mechanism to add v…KEVEPSS 3.5%analysed9.8CVE-2020-35481Solarwinds serv-u vulnerabilitySolarWinds Serv-U before 15.2.2 allows Unauthenticated Macro Injection.EPSS 1.3%9.1CVE-2026-28317Solarwinds serv-u insecure direct object reference vulnerabilitySolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires …EPSS 0.50%9.1CVE-2026-28312Solarwinds serv-u improper authorization vulnerabilitySolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system administrator and allow code exe…EPSS 0.58%9.1CVE-2026-28313Solarwinds serv-u insecure direct object reference vulnerabilitySolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary accoun…EPSS 0.50%

Source: NIST National Vulnerability Database (record CVE-2026-28321), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.