Impact
The vulnerability in SolarWinds Serv‑U allows a domain administrator to elevate their privileges to a system administrator. This is a privilege escalation flaw classified as CWE‑284. The immediate impact is that an attacker with domain administrative rights could gain full system control on the affected host. The severity is moderate, and the effect is reduced in Windows deployments according to the vendor statement.
Affected Systems
SolarWinds Serv‑U instances that are not running the latest version 2026.3 are potentially affected; the advisory does not specify exact version numbers. Affected users should determine whether their installation was built before the 2026.3 release and plan an upgrade if necessary.
Risk and Exploitability
The CVSS score of 4.7 indicates moderate risk, while the EPSS score of less than 1% suggests that exploitation is unlikely at present. The flaw is not listed in the CISA KEV catalog. The likely attack path assumes the attacker already possesses domain administrator credentials, from which the exploit elevates privileges to a system administrator. The advisory does not specify a network‑based vector, implying that the exploit would require local or domain-level access and would not necessarily expose the system to external attackers.
OpenCVE Enrichment