SB20260727223 - Multiple vulnerabilities in Serv-U FTP Server
Published: July 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 7 vulnerabilities.
1) Improper access control (CVE-ID: CVE-2026-28321)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote user to read and write arbitrary files.
The vulnerability exists due to broken access control in Serv-U when handling administrative actions. A remote privileged user can access files without proper authorization to read and write arbitrary files.
This issue requires domain administrator access and can be used to escalate privileges and execute code as root; the impact is lower on Windows installations.
2) Improper access control (CVE-ID: CVE-2026-28307)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper access control in group membership management when handling user group assignments. A remote privileged user can elevate a domain user group into an administrator group to escalate privileges.
The impact is lower in Windows deployments.
3) Cross-site scripting (CVE-ID: CVE-2026-28315)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear
The vulnerability allows a remote user to hijack an administrator session or disclose sensitive information.
The vulnerability exists due to cross-site scripting in Serv-U when processing stored content. A remote privileged user can inject a crafted script to hijack an administrator session or disclose sensitive information.
User interaction is required for an administrator to view the stored malicious content.
4) Authorization bypass through user-controlled key (CVE-ID: CVE-2026-28314)
CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote user to take over accounts.
The vulnerability exists due to improper access control in object reference handling when processing authenticated requests. A remote privileged user can access direct object references to take over accounts.
The impact is lower in Windows deployments.
5) Authorization bypass through user-controlled key (CVE-ID: CVE-2026-28313)
CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote user to take over arbitrary accounts.
The vulnerability exists due to an insecure direct object reference in the smtp-related account access controls when handling crafted object references. A remote privileged user can manipulate direct object references to take over arbitrary accounts.
The issue can lead to SMTP hijacking, and the impact is lower in Windows deployments.
6) Improper access control (CVE-ID: CVE-2026-28310)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper access control in user type management in Serv-U when handling administrative actions. A remote privileged user can elevate a domain administrator account to system administrator privileges to escalate privileges.
The impact is lower in Windows deployments.
7) Improper access control (CVE-ID: CVE-2026-28309)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote user to escalate privileges by creating system administrator accounts.
The vulnerability exists due to improper access control in Serv-U when handling administrative account management actions. A remote privileged user can create system administrator accounts to escalate privileges.
The impact is lower in Windows deployments.
Remediation
Install update from vendor's website.
References
- https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28321
- https://p1.aprimocdn.net/solarwinds/681cad7d-f433-4ee1-9094-b48e009af470/CVE-2026-28321_Original%20file.pdf
- https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28307
- https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28315
- https://p1.aprimocdn.net/solarwinds/73d2bd96-7a48-4adf-bdf4-b48e0079e1d7/CVE-2026-28315_Original%20file.pdf
- https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28314
- https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm
- https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28313
- https://p1.aprimocdn.net/solarwinds/f31888ea-a8c2-4a3d-a05c-b48e008034db/CVE-2026-28313_Original%20file.pdf
- https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28310
- https://p1.aprimocdn.net/solarwinds/b95d9727-ae10-4aed-83e5-b48e0082e8b3/CVE-2026-28310_Original%20file.pdf
- https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28309
- https://p1.aprimocdn.net/solarwinds/4208add7-07d2-4ccc-a8b7-b48e00c45b55/CVE-2026-28309_Original%20file.pdf