---
id: CVE-2025-40548
title: >-
  A missing validation process exists in Serv U when abused, could give a
  malicious actor with access to admin privileges the ability to execute code
summary: >-
  A missing validation process exists in Serv U when abused, could give a
  malicious actor with access to admin privileges the ability to execute code. 


  This issue requires administrative privileges to abuse. On Windows
  deployments, the ri…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-269
vendor: solarwinds
product: serv-u
affected:
  - serv-u < 15.5.3
patched:
  - serv-u 15.5.3
published: '2025-11-18'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T21:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-40548'
references:
  - url: >-
      https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_15-5-3_release_notes.htm
    label: psirt@solarwinds.com
  - url: 'https://www.solarwinds.com/trust-center/security-advisories/CVE-2025-40548'
    label: psirt@solarwinds.com
tags:
  - nvd
epss: 0.00699
epssPercentile: 0.51654
ingestedAt: '2026-10-07T21:54:15.068Z'
---

## Overview

A missing validation process exists in Serv U when abused, could give a malicious actor with access to admin privileges the ability to execute code. 

This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged service accounts by default.

## Affected

- `serv-u < 15.5.3`

## Remediation

Upgrade past the affected range:

- `serv-u 15.5.3`
