type: cve · created: 2026-09-20 · updated: 2026-09-20 · tags: [cve] · confidence: high · severity: critical · affected_sectors: [global] · au_impact: false
The same release cycle resolves a critical SAML authentication bypass in Web Help Desk (CVE-2026-28323, 9.8) that applies when SAML 2.0 authentication is enabled, plus a denial-of-service flaw in the same product (CVE-2026-28299, 8.2), and 16 flaws in Serv-U (CVE-2026-28302, CVE-2026-28304 through CVE-2026-28317, CVE-2026-28321 and CVE-2026-28323) that could enable privilege escalation, remote code execution and the creation of administrator accounts.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-28321 |
| CVSS | 9.1 (CVSS 3.1, Critical) |
| Vendor / product | SolarWinds Serv-U |
| Reported | 2026-09-20 |
NVD description
SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate privileges and execute code as root. A domain administrator access is required, and the impact is lower in Windows installations.