Improper access control in Serv-U FTP Server - CVE-2026-28321
Published: July 27, 2026
Serv-U FTP Server
Detailed vulnerability description
The vulnerability allows a remote user to read and write arbitrary files.
The vulnerability exists due to broken access control in Serv-U when handling administrative actions. A remote privileged user can access files without proper authorization to read and write arbitrary files.
This issue requires domain administrator access and can be used to escalate privileges and execute code as root; the impact is lower on Windows installations.