
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28316 is an Insecure Direct Object Reference (IDOR) vulnerability in SolarWinds Serv-U Managed File Transfer that enables privilege escalation to system administrator level, allowing an attacker to execute arbitrary commands as the root user on Linux/Unix systems. It affects SolarWinds Serv-U versions 15.5.4 HF1 and below (all versions prior to 2026.3). The vulnerability was published on July 21, 2026, and a fix was released the same day in Serv-U 2026.3. It carries a CVSS v3.1 base score of 9.1 (Critical) (SolarWinds Advisory, GitHub Advisory). The vulnerability was reported through the Intigriti Bug Bounty Program (Serv-U Release Notes).
The vulnerability is classified as CWE-639 (Authorization Bypass Through User-Controlled Key), where the application fails to properly validate that a user-controlled key corresponds to an object the authenticated user is authorized to access. An attacker with a domain administrator account can manipulate object references in API requests to access or modify resources belonging to higher-privileged accounts, ultimately escalating to system administrator privileges. This network-accessible attack requires no user interaction and has low attack complexity, though it does require existing domain administrator credentials as a precondition. The impact is notably lower on Windows deployments, suggesting the root-level command execution path is specific to Linux/Unix environments (SolarWinds Advisory, GitHub Advisory).
Successful exploitation allows a domain administrator to escalate privileges to system administrator and execute arbitrary commands as the root user on Linux/Unix-based Serv-U deployments, resulting in full confidentiality, integrity, and availability compromise of the affected system. An attacker achieving root-level command execution could exfiltrate all managed file transfer data, modify or destroy files, install backdoors, and potentially pivot to other systems on the network. The scope is marked as "Changed" in the CVSS scoring, indicating that the impact extends beyond the Serv-U application itself to the underlying operating system and potentially connected infrastructure (SolarWinds Advisory, GitHub Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 1.28% (67th percentile), indicating a moderate but not elevated near-term exploitation probability. The SSVC assessment classifies the vulnerability as non-automatable, with no known exploitation at this time. CVE-2026-28316 is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No specific threat actor attribution has been reported.
/var/log/auth.log or /var/log/secure) showing commands run as root by the Serv-U process (ServUDaemon) that are not part of normal operations.curl, wget, or nc) on Linux/Unix systems.SolarWinds has released a patch in Serv-U version 2026.3, which addresses CVE-2026-28316 along with 14 other critical vulnerabilities. All users running Serv-U 15.5.4 HF1 or earlier should upgrade to version 2026.3 immediately. As interim mitigations, organizations should restrict domain administrator account access to only those users who strictly require it, monitor for suspicious privilege escalation activities in Serv-U audit logs, and apply additional OS-level controls to limit root-level command execution on Linux/Unix hosts running Serv-U (SolarWinds Advisory, Serv-U Release Notes).
The disclosure of CVE-2026-28316 was part of a broader batch of 15 critical vulnerabilities patched in Serv-U 2026.3, which attracted significant media attention. Security outlets including GBHackers, CyberPress, CyberSecurityNews, and Heise reported on the release, highlighting the severity of the vulnerabilities and the potential for root-level remote code execution (GBHackers, CyberPress, Heise). The volume and severity of the simultaneous CVEs drew community commentary about the security posture of Serv-U, given SolarWinds' history with high-profile supply chain incidents. All vulnerabilities were responsibly disclosed through the Intigriti Bug Bounty Program (Serv-U Release Notes).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."