
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-40541 is an Insecure Direct Object Reference (IDOR) Remote Code Execution vulnerability in SolarWinds Serv-U that allows an authenticated attacker with administrative privileges to execute native code as a privileged account. It affects all versions of SolarWinds Serv-U prior to 15.5.4, including Serv-U 15.5.3 and earlier. The vulnerability was disclosed and patched on February 24, 2026. SolarWinds rates this as Critical with a CVSS v3.1 score of 9.1 (per the vendor advisory using a Changed scope vector), while NVD scores it at 7.2 (High) using an Unchanged scope (SolarWinds Advisory, Serv-U Release Notes).
The vulnerability is classified under CWE-639 (Authorization Bypass Through User-Controlled Key) and CWE-704 (Incorrect Type Conversion or Cast), indicating that an incorrect type conversion enables an IDOR condition where a user-controlled key bypasses authorization checks. An attacker with administrative access can manipulate object references to trigger native code execution as a privileged account. The flaw is network-exploitable with low attack complexity, requiring no user interaction, but does require high-privilege (administrative) credentials as a precondition. No public proof-of-concept exploit code has been identified at this time (SolarWinds Advisory, Serv-U Release Notes).
Successful exploitation allows a malicious actor with administrative privileges to execute arbitrary native code as a privileged (root/SYSTEM) account on the Serv-U host, resulting in complete compromise of confidentiality, integrity, and availability. On Linux deployments, the impact is particularly severe as Serv-U may run as root, enabling full system takeover; on Windows, the risk is somewhat reduced if the service runs under a less-privileged service account. This could lead to unauthorized access to sensitive file transfer data, modification of system configurations, installation of backdoors, and potential lateral movement within the network (SolarWinds Advisory, Serv-U Release Notes).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation as of the time of disclosure. The EPSS score is approximately 0.043%, reflecting a low near-term exploitation probability. CVE-2025-40541 has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires administrative-level credentials, which limits the attacker pool but does not eliminate risk from insider threats or compromised admin accounts (SolarWinds Advisory).
SolarWinds has released Serv-U version 15.5.4, which addresses CVE-2025-40541 along with three other critical RCE vulnerabilities (CVE-2025-40538, CVE-2025-40539, CVE-2025-40540). All versions prior to 15.5.4 are affected and should be updated immediately. As an interim measure, organizations should restrict administrative access to Serv-U systems to only necessary personnel and, where possible, configure Serv-U services on Windows to run under least-privileged service accounts to reduce the potential impact of exploitation. Monitor administrative access logs for suspicious activity pending upgrade (SolarWinds Advisory, Serv-U Release Notes).
The disclosure generated notable coverage across the security community, with outlets including The Hacker News, The Register, Security Affairs, Help Net Security, and CSO Online reporting on the batch of four critical Serv-U vulnerabilities patched simultaneously. Researchers and media highlighted the pattern of high-severity disclosures from SolarWinds, with CSO Online noting this extends "SolarWinds' run of high-severity disclosures." Security firms including Orca Security and SOCRadar published technical summaries, and the Belgian Centre for Cybersecurity issued a warning advisory urging immediate patching (The Hacker News, The Register, Orca Security, SOCRadar).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."