Improper access control in Serv-U FTP Server - CVE-2026-28307
Published: July 27, 2026
Serv-U FTP Server
Detailed vulnerability description
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper access control in group membership management when handling user group assignments. A remote privileged user can elevate a domain user group into an administrator group to escalate privileges.
The impact is lower in Windows deployments.