Executive brief
SolarWinds Serv-U, a managed file transfer and FTP server, is affected by a security flaw that allows for account takeover. An attacker can exploit this vulnerability to hijack the system's email notification settings, potentially leading to the compromise of user accounts and sensitive data. While the risk is present on all platforms, the impact is reportedly lower for organizations running the software on Windows.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability (CWE-639) exists in SolarWinds Serv-U versions 15.5.4 HF1 and below. The flaw allows an authenticated attacker with high privileges to manipulate object references to hijack SMTP configurations. This can be leveraged to facilitate arbitrary account takeovers across the platform. The vulnerability is reachable over the network without user interaction, though it requires high-level administrative privileges to execute. SolarWinds has addressed this issue in version 2026.3.
Affected products
- SolarWinds Serv-U 15.5.4 HF1 and below
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory