Executive brief
SolarWinds Serv-U, a managed file transfer and FTP server, is affected by a security flaw that allows an authorized domain administrator to gain full control over the underlying system. By exploiting this vulnerability, an attacker can escalate their privileges to the highest level (root), potentially leading to complete data exposure or total service disruption. The risk is particularly high for Linux-based deployments, though Windows systems are also affected to a lesser degree.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability (CWE-639) exists in SolarWinds Serv-U versions 15.5.4 HF1 and below. The flaw allows an attacker with existing domain administrator credentials to bypass authorization checks and escalate privileges to a system administrator level. On Linux deployments, this allows for command execution as the root user; the impact is reported as lower on Windows deployments. The attack is reachable over the network but requires high privileges (PR:H) as a precondition. SolarWinds has addressed this in version 2026.3.
Affected products
- SolarWinds Serv-U 15.5.4 HF1 and below
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory