Executive brief
SolarWinds Serv-U, a managed file transfer and FTP server, is affected by a critical security vulnerability. An attacker could exploit this flaw to remotely execute arbitrary commands on the server with high privileges (root). This could lead to a complete takeover of the file transfer system, unauthorized access to sensitive customer data, and potential disruption of business operations.
Technical details
SolarWinds Serv-U is vulnerable to remote code execution (RCE) due to improper access control (CWE-284). The vulnerability allows an authenticated attacker with high privileges to execute arbitrary code on the host system. On non-Windows deployments, this execution occurs with root privileges, while the impact is reportedly lower on Windows systems. The attack vector is network-based and does not require user interaction, though it does require high-level administrative credentials. SolarWinds has addressed this issue in Serv-U version 2026.3.
Affected products
- SolarWinds Serv-U 15.5.4 HF1 and below
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory