Impact
SolarWinds Serv‑U is vulnerable to an insecure direct object reference that enables an attacker to manipulate resource identifiers to hijack the SMTP service and perform arbitrary account takeover. By exploiting this flaw an attacker could gain the ability to send email, intercept communications, or otherwise take control of user accounts. The impact is reported to be lower in Windows deployments.
Affected Systems
The affected product is SolarWinds Serv‑U. Any installation running a version older than the 2026.3 release is vulnerable. The vendor has issued a recommendation to upgrade to Serv‑U 2026.3, which contains a fix for the IDOR flaw.
Risk and Exploitability
The CVSS score of 4.7 indicates a low‑severity risk, and the EPSS score of less than 1% suggests a very low probability of exploitation in the wild. Because the vulnerability is not listed in the CISA KEV, the threat is lower. Based on the description, the likely attack vector is inferred as manipulation of SMTP configuration interfaces to hijack the account. Additional complexity may be required on Windows, which reduces the overall threat.
OpenCVE Enrichment