SB20260727223 - Multiple vulnerabilities in Serv-U FTP Server
Published: July 27, 2026 Updated: July 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 16 vulnerabilities.
1) Improper access control (CVE-ID: CVE-2026-28321)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to read and write arbitrary files.
The vulnerability exists due to broken access control in Serv-U when handling administrative actions. A remote privileged user can access files without proper authorization to read and write arbitrary files.
This issue requires domain administrator access and can be used to escalate privileges and execute code as root; the impact is lower on Windows installations.
2) Improper access control (CVE-ID: CVE-2026-28307)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper access control in group membership management when handling user group assignments. A remote privileged user can elevate a domain user group into an administrator group to escalate privileges.
The impact is lower in Windows deployments.
3) Cross-site scripting (CVE-ID: CVE-2026-28315)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to hijack an administrator session or disclose sensitive information.
The vulnerability exists due to cross-site scripting in Serv-U when processing stored content. A remote privileged user can inject a crafted script to hijack an administrator session or disclose sensitive information.
User interaction is required for an administrator to view the stored malicious content.
4) Authorization bypass through user-controlled key (CVE-ID: CVE-2026-28314)
CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to take over accounts.
The vulnerability exists due to improper access control in object reference handling when processing authenticated requests. A remote privileged user can access direct object references to take over accounts.
The impact is lower in Windows deployments.
5) Authorization bypass through user-controlled key (CVE-ID: CVE-2026-28313)
CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to take over arbitrary accounts.
The vulnerability exists due to an insecure direct object reference in the smtp-related account access controls when handling crafted object references. A remote privileged user can manipulate direct object references to take over arbitrary accounts.
The issue can lead to SMTP hijacking, and the impact is lower in Windows deployments.
6) Improper access control (CVE-ID: CVE-2026-28310)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper access control in user type management in Serv-U when handling administrative actions. A remote privileged user can elevate a domain administrator account to system administrator privileges to escalate privileges.
The impact is lower in Windows deployments.
7) Improper access control (CVE-ID: CVE-2026-28309)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to escalate privileges by creating system administrator accounts.
The vulnerability exists due to improper access control in Serv-U when handling administrative account management actions. A remote privileged user can create system administrator accounts to escalate privileges.
The impact is lower in Windows deployments.
8) Authorization bypass through user-controlled key (CVE-ID: CVE-2026-28302)
CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to escalate privileges and execute arbitrary code as root.
The vulnerability exists due to insecure direct object reference in Serv-U when handling administrative object references. A remote user can access crafted object references to escalate privileges and execute arbitrary code as root.
This issue requires group administrator access. The impact is lower in Windows deployments.
9) Improper access control (CVE-ID: CVE-2026-28304)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code as root.
The vulnerability exists due to improper access control in Serv-U when handling requests. A remote attacker can send a specially crafted request to execute arbitrary code as root.
The impact is lower in Windows deployments.
10) Authorization bypass through user-controlled key (CVE-ID: CVE-2026-28305)
CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code as root.
The vulnerability exists due to insecure direct object reference in Serv-U when handling administrative object references. A remote user can access crafted object references to execute arbitrary code as root.
Exploitation requires a domain account with admin privileges and read and write access to the home directory. The impact is lower in Windows deployments.
11) Improper privilege management (CVE-ID: CVE-2026-28306)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper access control in Serv-U when managing administrator roles. A remote user can elevate an existing account to escalate privileges.
This issue allows a domain administrator to elevate their privileges to a system administrator. The impact is lower in Windows deployments.
12) Authorization bypass through user-controlled key (CVE-ID: CVE-2026-28308)
CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to insecure direct object reference in Serv-U when handling administrative object references. A remote user can access crafted object references to execute arbitrary code.
Domain administrator access is required. The impact is lower in Windows deployments.
13) Improper access control (CVE-ID: CVE-2026-28311)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper access control in Serv-U when modifying application behavior. A remote user can modify how the application behaves to execute arbitrary code.
This issue allows a domain administrator to modify application behavior in a way that leads to remote code execution. The impact is lower in Windows deployments.
14) Improper privilege management (CVE-ID: CVE-2026-28312)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to escalate privileges and execute arbitrary code as root.
The vulnerability exists due to improper access control in Serv-U when managing group access levels. A remote user can elevate a group's access level to escalate privileges and execute arbitrary code as root.
This issue elevates a group's access to system administrator. The impact is lower in Windows deployments.
15) Authorization bypass through user-controlled key (CVE-ID: CVE-2026-28316)
CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to escalate privileges and execute commands as the root user.
The vulnerability exists due to insecure direct object reference in Serv-U when handling administrative object references. A remote user can access crafted object references to escalate privileges and execute commands as the root user.
This issue requires a domain account with administrator access. The impact is lower in Windows deployments.
16) Authorization bypass through user-controlled key (CVE-ID: CVE-2026-28317)
CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to insecure direct object reference in Serv-U when handling administrative object references. A remote user can access crafted object references to escalate privileges.
Domain administrator access is required. The impact is lower in Windows deployments.
Remediation
Install update from vendor's website.
References
- https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28321
- https://p1.aprimocdn.net/solarwinds/681cad7d-f433-4ee1-9094-b48e009af470/CVE-2026-28321_Original%20file.pdf
- https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28307
- https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28315
- https://p1.aprimocdn.net/solarwinds/73d2bd96-7a48-4adf-bdf4-b48e0079e1d7/CVE-2026-28315_Original%20file.pdf
- https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28314
- https://documentation.solarwinds.com/en/success_center/servu/content/release_notes/servu_2026-3_release_notes.htm
- https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28313
- https://p1.aprimocdn.net/solarwinds/f31888ea-a8c2-4a3d-a05c-b48e008034db/CVE-2026-28313_Original%20file.pdf
- https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28310
- https://p1.aprimocdn.net/solarwinds/b95d9727-ae10-4aed-83e5-b48e0082e8b3/CVE-2026-28310_Original%20file.pdf
- https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28309
- https://p1.aprimocdn.net/solarwinds/4208add7-07d2-4ccc-a8b7-b48e00c45b55/CVE-2026-28309_Original%20file.pdf
- https://documentation.solarwinds.com/en/Success_Center/servu/Content/release_notes/servu_2026-3_release_notes.htm