CVE-2025-40549

CRITICAL

Solarwinds Serv-u < 15.5.3 - Path Traversal

Title source: rule

Description

A Path Restriction Bypass vulnerability exists in Serv-U that when abused, could give a malicious actor with access to admin privileges the ability to execute code on a directory. This issue requires administrative privileges to abuse. On Windows systems, this scored as medium due to differences in how paths and home directories are handled.

Scores

CVSS v3 9.1
EPSS 0.0024
EPSS Percentile 47.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Classification

CWE
CWE-22
Status published

Affected Products (1)

solarwinds/serv-u < 15.5.3

Timeline

Published Nov 18, 2025
Tracked Since Feb 18, 2026