Impact
SolarWinds Serv-U is impacted by an insecure direct object reference that allows an attacker who has domain administrator privileges to access or modify objects beyond their authorized scope, causing a privilege escalation. The vulnerability is rated with a CVSS score of 4.7, indicating moderate risk, and it is noted to have a lower impact on Windows deployments.
Affected Systems
The affected product is SolarWinds Serv-U. All versions prior to the 2026.3 release are vulnerable, as indicated by the vendor’s recommendation to upgrade to Serv-U 2026.3. This applies to deployments on both Windows and non‑Windows operating systems.
Risk and Exploitability
The EPSS score is less than 1%, and the vulnerability is not listed in the CISA KEV catalog, suggesting a low likelihood of widespread exploitation. However, because the attack requires domain administrator access, the threat is primarily internal and depends on the attacker having high‑level privileges. The CVSS score of 4.7 reflects the potential for local privilege escalation rather than a remote code execution scenario.
OpenCVE Enrichment