Impact
SolarWinds Serv‑U has a flaw that lets a user group that is normally granted domain permissions be elevated to the administrator group within the application. This weakness, identified as CWE‑284, allows non‑privileged users to gain administrative rights over the Serv‑U service, potentially exposing configuration data, user accounts, and files managed by the application. The description notes that in Windows deployments the impact is lower, but any elevation of privileges can compromise the system’s security posture.
Affected Systems
The vulnerability affects all installations of SolarWinds Serv‑U that run versions prior to 2026.3, as the advisory recommends upgrading to at least that release to eliminate the flaw. Users on earlier releases that rely on domain user groups for controlling service access are potential targets, regardless of the underlying operating system.
Risk and Exploitability
The CVSS score of 4.7 indicates moderate severity, while an EPSS score of less than 1% suggests a low probability of exploitation in practice. The vulnerability is not listed in the CISA KEV catalog. Attackers would likely need a legitimate domain account that is a member of a user group that can be promoted to administrators, implying a local or network-based privilege escalation scenario rather than a remote exploit. The restricted scope and low exploitation likelihood reduce overall risk, yet the potential to compromise service configuration warrants attention.
OpenCVE Enrichment