Impact
The vulnerability is an insecure direct object reference that allows an attacker who can provide or alter references to internal resources to cause the Serv-U server to execute arbitrary code with root privileges. The flaw can be triggered by a domain account that has administrative rights and read/write permission on its home directory, thereby giving the attacker the capability to run native system commands. While the description indicates that the impact is mitigated in Windows deployments, the potential for full system compromise remains in affected environments.
Affected Systems
SolarWinds Serv-U services are vulnerable. No specific version range was enumerated, but the vendor's recommendation is to upgrade to Serv-U 2026.3 once possible. All other earlier Serv-U releases that have not been patched remain at risk.
Risk and Exploitability
The CVSS score of 4.7 suggests a moderate severity, but the EPSS score of less than 1% implies that the probability of exploitation is low at present. The case is not listed in the CISA KEV catalog, which further indicates that no widespread exploit has been documented. Nonetheless, the attack vector requires privileged domain credentials and write access to the user's home directory; therefore, exploitation is best considered an insider threat or a targeted breach in which an attacker has already compromised a privileged account. Effective mitigation will rely on disabling or limiting those privileged rights and applying the vendor's patch.
OpenCVE Enrichment