Impact
SolarWinds Serv‑U is vulnerable to an insecure direct object reference that allows an attacker who already has domain administrator privileges to elevate their privileges to system administrator and execute commands as the root user. The vulnerability arises when object references can be manipulated, bypassing access controls to reach protected resources. The impact is less severe on Windows deployments, but on affected systems an attacker can achieve full control of the host.
Affected Systems
The vulnerability affects SolarWinds Serv‑U. All releases prior to the recommended Serv‑U 2026.3 are susceptible; the CVE advisory specifically advises upgrading to 2026.3 to remediate the issue. No exact version list is provided, but any earlier Serv‑U build remains at risk.
Risk and Exploitability
The CVSS score of 4.7 denotes moderate severity, and the EPSS score of 1% indicates a low but nonzero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a domain account with administrator access, limiting the threat to internal actors or compromised administrator accounts. The attack vector is likely internal and involves manipulating direct object references within the application flow.
OpenCVE Enrichment