SolarWinds Serv-U 2026.3, 15 critical IDOR flaws let authenticated users escalate to root RCE on the file-transfer server (CVSS 9.1)
SolarWinds patches 15 critical IDOR-to-root flaws in the internet-facing Serv-U managed-file-transfer server
Defender actions
- Update SolarWinds Serv-U to 2026.3 now and prune domain- and group-administrator role assignments, the escalation chain pivots off an over-privileged authenticated account, so reducing that account population shrinks the exploitable surface immediately.
Analysis
Serv-U 2026.3, released 2026-07-21, fixes 16 vulnerabilities (15 of them critical at CVSS 9.1) that are insecure-direct-object-reference (IDOR, CWE-639) and broken-access-control flaws in the managed-file-transfer web console rather than memory-safety bugs (SolarWinds, 2026-07-21). The consequential path is authorization: an authenticated user (in several cases needing only group- or domain-administrator scope, not full system administrator) can escalate to system administrator and achieve remote code execution as root on the underlying host, with reduced impact on Windows deployments (SolarWinds PSIRT, 2026-07-21; NCSC Switzerland, 2026-07-22). Individual flaws cover privilege escalation via configuration-path modification, arbitrary system-administrator account creation, arbitrary file read/write, account takeover through IDOR, and domain-user-group elevation to an admin group; one medium issue (CVE-2026-28315, CVSS 6.2) is a stored XSS in the admin UI usable for session hijacking. All were reported through SolarWinds' Intigriti bug-bounty program and NCSC-CH records exploitation status as unknown; heise notes Serv-U's history as a target for the Cl0p affiliate in prior MOVEit-class campaigns purely as context for why file-transfer software patch-lag is a recurring high-value target class (heise online, 2026-07-22).
Cited evidence
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root.
Successful exploitation allows authenticated attackers to escalate privileges to system administrator and execute arbitrary code with root privileges via network access.
Sources4
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.