Impact
SolarWinds Serv-U is vulnerable to a privilege escalation flaw that permits an account with domain administrator privileges to elevate to a system administrator role. The weakness, identified as CWE-862 (Insufficient Privilege Management), enables a local attacker to increase their authority over the Serv-U installation, potentially giving full control over server configuration and sensitive data. The effect is less severe in Windows-based deployments, according to the vendor’s description.
Affected Systems
The vulnerability affects all versions of SolarWinds Serv-U that are currently in use. SolarWinds recommends applying the Serv-U 2026.3 release, which contains the fix for this issue, as an immediate remediation. Users running Windows systems should also verify that the upgraded version behaves as expected, although the impact is reported to be lower on such platforms.
Risk and Exploitability
The CVSS score of 4.7 indicates that the flaw is of moderate severity, and the EPSS score, being less than 1%, suggests a low probability of exploitation at present. It is not listed in CISA’s KE vector requires an authenticated domain administrator to trigger the escalation, implying that internal users or compromised domain credentials could be used to exploit the flaw. Because the vulnerability requires existing administrative access, an attacker would need the ability to log into the Serv-U environment, after which the privilege jump can occur without additional effort.
OpenCVE Enrichment