SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-28309

CRITICAL · CVSS 9.1 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

A broken access control vulnerability in SolarWinds Serv-U allows a domain administrator to create system administrator accounts, potentially leading to unauthorized access and privilege escalation. While the impact is lower in Windows deployments, organizations using this software should prioritize remediation due to the critical nature of the vulnerability. System administrators and security teams should assess their environments for affected versions and implement necessary patches or mitigations.

CVE
CVE-2026-28309
Severity
CRITICAL
CVSS
9.1
EPSS
0.34%
Windows

Original NVD Description

SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. The impact is lower in Windows deployments.

Related CVEs

Other vulnerabilities affecting the same vendor(s)