Impact
SolarWinds Serv-U has a privilege escalation flaw that allows an attacker to elevate a group’s permissions to system administrator, thereby enabling code execution with root privileges. The vulnerability is less damaging in Windows deployments, but the core issue remains the same. The flaw permits elevation of privileges for groups that should not have administrative access, leading to full control over the server.
Affected Systems
The affected product is SolarWinds, but the vendor recommends upgrading to Serv-U version 2026.3 as soon as possible to address the issue.
Risk and Exploitability
The CVSS score of 4.7 indicates a moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not currently included in the CISA KEV catalog, reducing the immediate threat level. The most likely attack vector is an attacker who already has access to the Serv-U server, such as a user with limited group rights, who can manipulate group memberships to gain higher privileges. Once the group is elevated, the attacker can execute arbitrary code as root.
OpenCVE Enrichment