Impact
SolarWinds Serv-U is vulnerable to a broken access control flaw that allows a domain administrator to create system administrator accounts. The flaw enables users with domain admin rights to gain full control of the Serv-U application, effectively elevating their privileges. This elevated access could be used to read, modify, or delete sensitive data, deploy malicious software, or maintain persistent presence within the environment. The effect is limited to users who already hold domain administrative privileges, and the impact is reduced in Windows deployments according to the vendor's commentary.
Affected Systems
The affected product is SolarWinds Serv-U, with the vendor specifically identified as SolarWinds:Serv-U. No explicit version range is listed in the advisory, but the vendor recommends moving to Serv‑U version 2026.3 or newer as soon as practical. Users of earlier Serv‑U releases that have not applied this update remain vulnerable, and the advisory explicitly mentions a lower impact in Windows deployments.
Risk and Exploitability
The CVSS score of 4.7 places this vulnerability in the moderate range, and an EPSS score of exploitation in the wild. The flaw is not listed in the CISA KEV catalog, suggesting no known active exploits have been observed. Exploitation requires an attacker to already be a domain administrator, so the attack vector is internal and relies on legitimate domain administrative privileges. Due to the precision of the flaw in the Serv‑U code base, an attacker could create privileged accounts with little effort once inside the domain. The moderate score and low EPSS imply that the overall risk is moderate, but the potential impact on confidentiality, integrity, and availability justifies immediate remediation.
OpenCVE Enrichment