Impact
SolarWinds Serv‑U is affected by an insecure direct object reference vulnerability that allows an authenticated user to take control of another account by accessing resources they should not be able to reach. The weakness is classified as CWE‑639 and leads to account takeover, which could expose data and grant additional control over the system.
Affected Systems
SolarWinds Serv‑U in all affected deployments is vulnerable. Specific versions are not listed, but the vendor recommends upgrading to version 2026.3 to remediate the issue. The impact is lower in Windows deployments.
Risk and Exploitability
The CVSS score of 4.7 indicates moderate risk, and the EPSS score of less than 1% suggests exploitation is unlikely in the near term. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires valid authentication. Based on the description, it can be inferred that the IDOR flaw is triggered via the Serv‑U web interface, allowing a remote authenticated attacker to abuse the reference and obtain another user’s account.
OpenCVE Enrichment