Impact
SolarWinds Serv‑U has an insecure direct object reference flaw that can be used by a malicious actor to access privileged resources and potentially execute code with root privileges. The vulnerability requires the attacker to possess group administrator credentials; the impact is mitigated in Windows deployments. The weakness is a classic case of IDOR, allowing bypass of intended access controls.
Affected Systems
SolarWinds Serv‑U, versions earlier than 2026.3. The advisory does not list specific legacy versions, but the recommendation is to upgrade to Serv‑U 2026.3 to address the issue.
Risk and Exploitability
With a CVSS score of 4.7 the risk is moderate, and the EPSS score of less than 1% indicates a low probability of active exploitation today. The flaw is not part of the CISA KEV catalog. The likely attack path involves accessing the web‑based management interface and supplying a crafted resource reference that bypasses group‑level restrictions, elevating privileges to a root‑oriented state if the attacker already holds group admin rights.
OpenCVE Enrichment