Executive brief
SolarWinds Serv-U, a managed file transfer and FTP server, is affected by a security flaw that allows users with domain administrator privileges to gain higher-level system permissions. While the vulnerability is rated as critical, the practical impact is lower for organizations running the software on Windows. An exploit could allow an attacker who already has significant access to further compromise the underlying server or manipulate sensitive file transfer operations.
Technical details
SolarWinds Serv-U contains an insecure direct object reference (IDOR) vulnerability (CWE-639) in its authorization logic. An attacker with Domain Administrator privileges can exploit this flaw to escalate their privileges within the system. The attack is reachable over the network but requires high-level existing permissions (PR:H). The impact is reportedly lower in Windows-based deployments compared to other platforms. SolarWinds has addressed this issue in Serv-U version 2026.3.
Affected products
- SolarWinds Serv-U 15.5.4 HF1 and below
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory