Improper access control in Serv-U FTP Server - CVE-2026-28321

 

Improper access control in Serv-U FTP Server - CVE-2026-28321

Published: July 27, 2026


Vulnerability identifier: #VU139620
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2026-28321
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: SolarWinds
Affected software:
Serv-U FTP Server

Detailed vulnerability description

The vulnerability allows a remote user to read and write arbitrary files.

The vulnerability exists due to broken access control in Serv-U when handling administrative actions. A remote privileged user can access files without proper authorization to read and write arbitrary files.

This issue requires domain administrator access and can be used to escalate privileges and execute code as root; the impact is lower on Windows installations.


How to mitigate CVE-2026-28321

Install security update from vendor's website.

Sources