Executive brief
SolarWinds Serv-U, a managed file transfer and FTP server, is affected by a security flaw that allows an attacker to gain full control over the system. By exploiting an authorization bypass, a user with group administrator privileges can elevate their access to execute commands as the root user. This could lead to a complete compromise of the server, including the theft or deletion of sensitive files and disruption of business operations.
Technical details
SolarWinds Serv-U (version 15.5.4 HF1 and below) contains an Insecure Direct Object Reference (IDOR) vulnerability, classified as CWE-639. The flaw allows an attacker with existing group administrator privileges to bypass authorization checks by manipulating user-controlled keys. Successful exploitation enables the attacker to escalate privileges and achieve remote code execution with root/system-level authority. While the vulnerability is network-reachable, it requires high privileges (PR:H) to execute. The impact is noted to be lower on Windows deployments compared to Linux. SolarWinds has addressed this in version 2026.3.
Affected products
- SolarWinds Serv-U 15.5.4 HF1 and below
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory