Impact
SolarWinds Serv‑U suffers a broken access control flaw that allows an attacker with domain administrator rights to read and write arbitrary files on the server. By exploiting this vulnerability the attacker can elevate privileges to the root level and subsequently execute arbitrary code. The flaw is identified as CWE‑284 and has a CVSS score of 4.7. Although the impact is mitigated on Windows installations, the issue remains significant on non‑Windows systems.
Affected Systems
Serv‑U versions prior to 2026.3 are affected. All customers running these versions should upgrade to Serv‑U 2026.3 or later as soon as practicable, following the vendor’s recommendation.
Risk and Exploitability
The CVSS score of 4.7 indicates moderate severity, and an EPSS score of less than 1% reflects a very low probability of exploitation in production environments. The vulnerability is not listed in CISA KEV. Attackers require domain administrator access, so the risk is constrained by access control policies but, if achieved, can lead to full system compromise.
OpenCVE Enrichment