Impact
SolarWinds Serv‑U is vulnerable to a stored cross‑site scripting flaw that can be abused by authenticated administrators. An attacker who can inject crafted input into the application may cause a victim’s browser to execute malicious script in the context of the administrator account, potentially allowing session hijacking and the leakage of sensitive information.
Affected Systems
The vulnerability affects SolarWinds Serv‑U for authenticated administrators who can log in and enter data into the web interface. The issue is present in versions prior to the release of Serv‑U 2026.3; exact version ranges are not enumerated in the advisory, instances should be evaluated for the presence of the flaw.
Risk and Exploitability
The CVSS score of 6.2 reflects a medium impact for a user with administrative access. The EPSS score indicates a very low exploitation probability at present (<1%). The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through normal authenticated usage of the Serv‑U application, where an attacker can store malicious script data that later executes when an administrator views the affected content.
OpenCVE Enrichment