Executive brief
SolarWinds Serv-U, a managed file transfer and FTP server, is affected by a security flaw that allows users with domain administrator privileges to improperly create full system administrator accounts. This could allow a restricted administrator to gain complete control over the entire file transfer server and its underlying configuration. While the risk is present on both Windows and Linux, the impact is reported to be lower on Windows deployments.
Technical details
A broken access control vulnerability (CWE-862) exists in SolarWinds Serv-U versions 15.5.4 HF1 and below. The flaw allows an authenticated attacker with Domain Administrator privileges to bypass intended authorization restrictions and create System Administrator accounts, effectively escalating their privileges to the highest level within the application. The attack is reachable over the network without user interaction, though it requires high-level existing privileges (PR:H). The vulnerability has a higher impact on Linux deployments compared to Windows. SolarWinds has addressed this issue in Serv-U version 2026.3.
Affected products
- SolarWinds Serv-U 15.5.4 HF1 and below
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory