PT-2026-21671 · Serv-U · Serv-U

Published

2026-02-24

·

Updated

2026-03-10

·

CVE-2025-40541

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Serv-U versions 15.5.3 and earlier
Description An Insecure Direct Object Reference (IDOR) vulnerability exists in Serv-U. Exploitation of this issue allows a malicious actor to execute native code as a privileged account. This requires administrative privileges to abuse. On Windows deployments, the risk is considered medium because services often run under less-privileged service accounts. The vulnerability allows an attacker to access or manipulate objects directly by manipulating parameters or identifiers without proper authorization checks.
Recommendations Serv-U versions 15.5.3 and earlier should be updated to version 15.5.4 or later.

Fix

RCE

IDOR

Incorrect Type Conversion or Cast

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-40541

Affected Products

Serv-U