Impact
SolarWinds Serv-U is vulnerable to an insecure direct object reference that permits an attacker to manipulate URL parameters and gain access to files or commands outside the intended scope. This weakness can ultimately lead to the execution of arbitrary code on the server, granting full control over the affected system. The flaw is listed as CWE-639, indicating that it arises from improper authorization checks on object references.
Affected Systems
The affected product is SolarWinds Serv-U, and the CVE does not specify which versions are impacted; however, the advisory recommends upgrading to 2026.3. The flaw is particularly relevant for deployments where the application is installed on Windows servers and accessed by domain administrators, though the impact is lower when Serv-U runs under a restricted, non-domain realm account.
Risk and Exploitability
The CVSS score of 4.7 reflects a moderate risk, but the requirement for domain administrator credentials limits the attack surface. The EPSS score of less than 1% indicates a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, because the flaw can result in remote code execution if harnessed, it should be treated as a priority for patching, especially in environments where Serv-U services are exposed to internal or external networks.
OpenCVE Enrichment