
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-40538 is a broken access control vulnerability in SolarWinds Serv-U that allows a malicious actor with domain admin or group admin privileges to create a system administrator account and execute arbitrary code as a privileged account. It affects all Serv-U versions prior to 15.5.4 and was disclosed on February 24, 2026. The vulnerability carries a CVSS v3.1 base score of 9.1 (Critical) per the SolarWinds advisory, though NVD scores it at 7.2 (High) — the discrepancy reflects differing scope assessments, with SolarWinds noting a Changed scope on Linux deployments and a Medium risk on Windows where services run under less-privileged accounts (SolarWinds Advisory, Serv-U 15.5.4 Release Notes).
The vulnerability is classified as CWE-269 (Improper Privilege Management) and stems from broken access control logic within Serv-U's administrative interface. A domain admin or group admin — roles that are subordinate to system admin — can exploit insufficient authorization checks to elevate their privileges by creating a new system administrator account, then leverage that account to execute arbitrary code as root (on Linux) or as the service account (on Windows). The attack vector is network-based, requires no user interaction, and has low attack complexity, but does require the attacker to already possess domain or group admin credentials within the Serv-U environment (SolarWinds Advisory, Serv-U 15.5.4 Release Notes).
Successful exploitation allows an attacker to create unauthorized system administrator accounts and execute arbitrary code with the highest available privileges — root on Linux deployments, or the service account on Windows. This results in high impact to confidentiality, integrity, and availability of the Serv-U system, potentially enabling full server takeover, data exfiltration of all managed file transfers, and use of the compromised server as a pivot point for lateral movement within the network. On Windows, the risk is somewhat reduced because Serv-U services frequently run under less-privileged service accounts by default (SolarWinds Advisory, Serv-U 15.5.4 Release Notes).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The EPSS score is approximately 0.026%, indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires the attacker to already hold domain admin or group admin credentials within the Serv-U environment, which limits the attack surface compared to unauthenticated vulnerabilities. No threat actor attribution has been reported (SolarWinds Advisory).
/etc, /opt) by the Serv-U process./bin/bash, /bin/sh) or network utilities (curl, wget, nc) on Linux hosts.SolarWinds has released Serv-U 15.5.4 (released February 24, 2026) to address this vulnerability; all organizations running Serv-U versions prior to 15.5.4 should upgrade immediately (Serv-U 15.5.4 Release Notes, SolarWinds Advisory). No vendor-provided workaround is available for those unable to patch immediately. As interim mitigations, organizations should restrict domain admin and group admin privileges to only trusted personnel with a legitimate need, implement strong monitoring and alerting for new system administrator account creation, and review existing Serv-U admin accounts for unauthorized additions.
The disclosure generated significant coverage across security media, with outlets including BleepingComputer, The Register, SecurityAffairs, HelpNet Security, and CSO Online reporting on the four critical Serv-U flaws patched simultaneously, framing them as enabling "root access" to servers (BleepingComputer, The Register). Government CERTs including Canada's CCCS, Belgium's CCB, and Thailand's ThaiCERT issued advisories urging prompt patching. Community discussion on Reddit and Mastodon highlighted the pattern of high-severity disclosures from SolarWinds Serv-U, with CSO Online noting this extends "SolarWinds' run of high-severity disclosures" (CSO Online). Orca Security published a technical blog post analyzing the RCE vulnerabilities in the batch (Orca Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."