Serv-U Admin Roles Do Not Contain Blast Radius

Serv-U’s delegated admin model is not a safety boundary. If a domain or group admin account is compromised, these flaws let that account cross into system or root control, so role separation does not contain the blast radius. SolarWinds and NCSC say Serv-U had 15 fixed flaws, mostly IDOR and broken access control, plus stored XSS and related authorization bugs. The issues can support privilege escalation to system administrator or root, remote code execution, SMTP session hijacking, account takeover, and admin session compromise. SolarWinds says the fix is Serv-U 2026.3, and the advisory describes the problem as strongest in Evil Admin scenarios that start from already-authenticated high privilege access.

Part of the PlainSec briefing for 2026-07-27

Sources