Improper access control in Serv-U FTP Server - CVE-2026-28321

 

Improper access control in Serv-U FTP Server - CVE-2026-28321

Published: July 27, 2026


Vulnerability identifier: #VU139620
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-28321
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to read and write arbitrary files.

The vulnerability exists due to broken access control in Serv-U when handling administrative actions. A remote privileged user can access files without proper authorization to read and write arbitrary files.

This issue requires domain administrator access and can be used to escalate privileges and execute code as root; the impact is lower on Windows installations.


Affected software

Serv-U FTP Server

How to mitigate CVE-2026-28321

Install security update from vendor's website.

Serv-U FTP Server - update to 2026.3

External References

Related Security Bulletins