Broken Access Control Vulnerability in Serv-U by SolarWinds
CVE-2025-40538
9.1CRITICAL
What is CVE-2025-40538?
A vulnerability exists in Serv-U that allows an unauthorized actor to exploit broken access control mechanisms, enabling them to create system admin accounts. This access can lead to the execution of arbitrary code with elevated privileges, potentially compromising the entire system. The risk is particularly notable on Windows deployments where services often operate under less-privileged accounts by default.
Affected Version(s)
Serv-U Windows SolarWinds Serv-U 15.5.3 and prior versions