Impact
SolarWinds Serv‑U is vulnerable to a remote code execution flaw that can allow an attacker to run arbitrary code with root privileges when the vulnerability is exploited. The weakness stems from improper access control (CWE‑284). In Windows deployments the impact is lower, but on Unix‑based systems the attacker could gain full system compromise.
Affected Systems
All affected installations of SolarWinds Serv‑U prior to the release of version 2026.3. The vendor specifically advises upgrading to Serv‑U 2026.3 to address the flaw. No precise affected version range was disclosed, so any instance running a pre‑2026.3 build should be considered vulnerable.
Risk and Exploitability
The CVSS score of 4.7 indicates a moderate severity overall, but the nature of the flaw—remote code execution—yields a high potential impact. The EPSS score of less than 1 % suggests low exploitation likelihood, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector is remote network access to the Serv‑U service, with exploitation through normal client connections, assuming sufficient privileges are not enforced.
OpenCVE Enrichment