External risk intelligence

SolarWinds Serv-U Broken Access Control Allows Domain Admin to Create System Admins.

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-28309

SolarWinds Serv-U is a file transfer server application designed to facilitate remote file management and transfers. Such applications are commonly deployed as internet-facing services to allow external users or partners to access, upload, or download files, making the management interface and service endpoints frequently reachable from the public internet.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability in SolarWinds Serv-U allows a privileged user to escalate their access to system administrator rights, potentially leading to unauthorized control over the system. This issue is particularly concerning due to the nature of Serv-U's role in file transfer and remote management, which often involves sensitive data and critical business operations. The primary concern is to confirm if this specific technology is in use and assess the potential exposure.

  • Broken access control allows privilege escalation.
  • High impact if domain admins can create sysadmins.
  • Confirm if Serv-U is deployed and exposed.

Attack Path

How an attacker could exploit the issue

An attacker with existing domain or group administrator privileges can leverage a broken access control vulnerability to create a system administrator account. This elevated access can then be used to execute arbitrary code on the system. The risk is lower in Windows deployments because Serv-U services often run with less privileged accounts by default.

  • Requires administrator credentials.
  • Vulnerability triggered by account creation.
  • Risk of arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

A broken access control vulnerability in SolarWinds Serv-U could allow a domain administrator to create system administrator accounts. This could lead to elevated privileges and unauthorized access to system functions when supported by the advisory's described conditions.

  • System administrator privileges could be created.
  • Unauthenticated access may grant elevated privileges.
  • Unauthorized system control may occur.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in SolarWinds Serv-U, allowing domain administrators to create system administrator accounts, primarily impacts the application and infrastructure teams responsible for its deployment and management. The initial focus should be on identifying all instances of Serv-U, assessing their exposure and criticality, and confirming the designated owner for remediation.

  • Application and infrastructure teams own this.
  • Verify Serv-U instance reachability and criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is SolarWinds Serv-U?

SolarWinds Serv-U is a specialized software application used to manage and transfer files across networks. Organizations deploy it as a central hub where internal users or external partners can securely upload and download data. Because of its core function, it is frequently configured to be accessible over the network to facilitate these remote file management tasks.

What does broken access control mean for CVE-2026-28309?

This vulnerability is classified as CWE-862, which refers to missing or incorrect authorization checks. In this specific case, the software fails to properly verify if a user has the appropriate permissions before allowing them to perform sensitive actions. Consequently, an existing domain administrator can bypass standard security restrictions to incorrectly grant themselves the much higher authority of a system administrator.

How is this vulnerability triggered?

An attacker must already possess valid domain or group administrator credentials to trigger this flaw. The vulnerability is activated specifically when a user with these lower-level administrative rights attempts to create a new system administrator account. It is important to note that unauthorized individuals without these initial administrator credentials cannot trigger the bug, and the impact is reduced on systems running the Windows operating system.

Do I need to worry about my Serv-U instance?

You should prioritize this if your instance is internet-facing. According to Halo Surface Signal, Serv-U is commonly deployed as a public-facing service, meaning its management interfaces are often reachable from the open internet. If your deployment is accessible globally, it presents a larger attack surface, making it vital to confirm whether your specific installation is reachable by external parties.

When should I take action for this vulnerability?

You should begin by identifying all instances of Serv-U within your environment immediately. Since this issue involves privilege escalation, work with your infrastructure teams to verify which systems are running the software, determine their criticality to your business, and confirm who is responsible for managing them. Following this identification, you can plan the appropriate steps to mitigate the risks associated with unauthorized administrative access.

References