Executive brief
SolarWinds Serv-U, a managed file transfer and FTP server, is affected by a security flaw that allows users with existing group access to elevate their privileges to system administrator. On Linux-based systems, this allows an attacker to take full control of the server and execute commands with root-level authority, potentially leading to data theft or complete service disruption. While the impact is slightly lower on Windows deployments, the vulnerability still poses a significant risk to organizational data and infrastructure.
Technical details
A privilege escalation vulnerability exists in SolarWinds Serv-U due to improper authorization (CWE-285). An attacker with high-privileged credentials (such as group-level access) can exploit this flaw to elevate their permissions to system administrator. On Linux deployments, this leads to arbitrary code execution with root privileges; the impact is reported as lower on Windows systems but still critical. The vulnerability is reachable over the network without user interaction. SolarWinds has addressed this issue in Serv-U version 2026.3.
Affected products
- SolarWinds Serv-U 15.5.4 HF1 and below
Timeline
- 2026-07-21: advisory: Initial advisory published by SolarWinds and NVD
- 2026-07-21: patched: Fixed in Serv-U version 2026.3