
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-40548 is a Broken Access Control Remote Code Execution vulnerability in SolarWinds Serv-U, classified as "SolarWinds Serv-U Broken Access Control - Remote Code Execution Vulnerability." A missing validation process in Serv-U allows a malicious actor with administrative privileges to execute arbitrary code on the affected system. All versions of Serv-U prior to 15.5.3 (specifically 15.5.2 and earlier) are affected. The vulnerability was first published on November 18, 2025, with a fix released the same day in version 15.5.3. It carries a CVSS v3.1 base score of 9.1 (Critical), though on Windows deployments the risk is scored as medium due to services typically running under less-privileged service accounts (SolarWinds Advisory, Serv-U Release Notes).
The root cause is classified as CWE-269 (Improper Privilege Management), specifically a missing validation process within Serv-U's access control logic. An attacker who already holds administrative credentials can abuse this gap to bypass intended access restrictions and trigger arbitrary code execution on the server. The attack vector is network-based, requires no user interaction, and has low attack complexity, but does require high privileges (administrative access) as a precondition. The vulnerability is distinct from the co-disclosed CVE-2025-40547 (logic error) and CVE-2025-40549 (path restriction bypass), all three of which were patched simultaneously in version 15.5.3 (SolarWinds Advisory, Serv-U Release Notes).
Successful exploitation allows an authenticated administrator to execute arbitrary code on the Serv-U server, resulting in high impact to confidentiality, integrity, and availability. The CVSS scope is marked as "Changed," indicating that exploitation can affect resources beyond the Serv-U application itself, potentially enabling full system compromise. On Linux deployments, the risk is particularly severe as Serv-U may run under a highly privileged account; on Windows, the impact is somewhat mitigated by typical service account configurations. Data exfiltration, lateral movement within the network, and persistent access are all plausible outcomes of successful exploitation (SolarWinds Advisory, Serv-U Release Notes).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (SolarWinds Advisory). The EPSS score is approximately 0.026%, reflecting a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires administrative credentials, which significantly raises the bar for opportunistic attackers, though insider threats or compromised admin accounts remain a realistic attack path.
SolarWinds has released a patch in Serv-U version 15.5.3, which addresses CVE-2025-40548 along with two other critical vulnerabilities (CVE-2025-40547 and CVE-2025-40549). All organizations running Serv-U 15.5.2 or earlier should upgrade to 15.5.3 immediately. As interim measures, organizations should restrict administrative access to Serv-U to trusted personnel only, implement least-privilege principles, apply network segmentation to limit exposure of the Serv-U management interface, and monitor for unauthorized administrative activity (SolarWinds Advisory, Serv-U Release Notes).
The vulnerability received coverage from multiple security news outlets including SecurityOnline, GBHackers, CyberSecurityNews, SecurityAffairs, and The Hacker News (in a weekly recap), all noting the critical CVSS score and the requirement for admin privileges. Community discussion on Reddit (r/pwnhub) and Mastodon (infosec.exchange) highlighted the patch release and the broader context of three simultaneous critical Serv-U CVEs. The general sentiment was that while the severity score is high, the admin-privilege prerequisite meaningfully limits the realistic attack surface for most organizations (SecurityAffairs, The Hacker News).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."