CVE-2025-40538: SolarWinds Serv-U Broken Access Control Remote Code Execution Vulnerability
A broken access control vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to create a system admin user and execute arbitrary code as a privileged account via domain admin or group admin privileges.
This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged service accounts by default.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40538?
CVE-2025-40538 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2025-40538?
To fix CVE-2025-40538, update to the latest version of SolarWinds Serv-U that addresses this vulnerability.
What types of access does CVE-2025-40538 affect?
CVE-2025-40538 affects access controls, allowing unauthorized users to gain admin privileges.
Who is affected by CVE-2025-40538?
Organizations using SolarWinds Serv-U are affected by CVE-2025-40538, particularly those with insecure configurations.
What could an attacker do by exploiting CVE-2025-40538?
An attacker exploiting CVE-2025-40538 can create a system admin user and execute arbitrary code with elevated privileges.