SB20260727223 - Multiple vulnerabilities in Serv-U FTP Server



SB20260727223 - Multiple vulnerabilities in Serv-U FTP Server

Published: July 27, 2026

Security Bulletin ID SB20260727223
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 7
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 7 vulnerabilities.


1) Improper access control (CVE-ID: CVE-2026-28321)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to read and write arbitrary files.

The vulnerability exists due to broken access control in Serv-U when handling administrative actions. A remote privileged user can access files without proper authorization to read and write arbitrary files.

This issue requires domain administrator access and can be used to escalate privileges and execute code as root; the impact is lower on Windows installations.


2) Improper access control (CVE-ID: CVE-2026-28307)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to escalate privileges.

The vulnerability exists due to improper access control in group membership management when handling user group assignments. A remote privileged user can elevate a domain user group into an administrator group to escalate privileges.

The impact is lower in Windows deployments.


3) Cross-site scripting (CVE-ID: CVE-2026-28315)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear


The vulnerability allows a remote user to hijack an administrator session or disclose sensitive information.

The vulnerability exists due to cross-site scripting in Serv-U when processing stored content. A remote privileged user can inject a crafted script to hijack an administrator session or disclose sensitive information.

User interaction is required for an administrator to view the stored malicious content.


4) Authorization bypass through user-controlled key (CVE-ID: CVE-2026-28314)

CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to take over accounts.

The vulnerability exists due to improper access control in object reference handling when processing authenticated requests. A remote privileged user can access direct object references to take over accounts.

The impact is lower in Windows deployments.


5) Authorization bypass through user-controlled key (CVE-ID: CVE-2026-28313)

CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to take over arbitrary accounts.

The vulnerability exists due to an insecure direct object reference in the smtp-related account access controls when handling crafted object references. A remote privileged user can manipulate direct object references to take over arbitrary accounts.

The issue can lead to SMTP hijacking, and the impact is lower in Windows deployments.


6) Improper access control (CVE-ID: CVE-2026-28310)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to escalate privileges.

The vulnerability exists due to improper access control in user type management in Serv-U when handling administrative actions. A remote privileged user can elevate a domain administrator account to system administrator privileges to escalate privileges.

The impact is lower in Windows deployments.


7) Improper access control (CVE-ID: CVE-2026-28309)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote user to escalate privileges by creating system administrator accounts.

The vulnerability exists due to improper access control in Serv-U when handling administrative account management actions. A remote privileged user can create system administrator accounts to escalate privileges.

The impact is lower in Windows deployments.


Remediation

Install update from vendor's website.