Executive brief
SolarWinds Serv-U, a managed file transfer and FTP server, is affected by a security flaw that could allow an administrative user to take full control of the underlying server. By exploiting an authorization bypass, an attacker with specific directory access can execute commands with the highest level of system privileges (root). This could lead to a complete compromise of the server, including the theft or deletion of sensitive files and the disruption of file transfer services.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability (CWE-639) exists in SolarWinds Serv-U versions 15.5.4 HF1 and earlier. The flaw allows an attacker to bypass authorization by manipulating user-controlled keys to access or modify objects they should not have permission to reach. To exploit this, an attacker requires a domain account with administrative privileges and both read and write access to the home directory. Successful exploitation allows for remote code execution with root privileges on Linux deployments, though the impact is reportedly lower on Windows systems. The vulnerability is addressed in Serv-U version 2026.3.
Affected products
- SolarWinds Serv-U 15.5.4 HF1 and below
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory