Authorization bypass through user-controlled key in Serv-U FTP Server - CVE-2026-28313

 

Authorization bypass through user-controlled key in Serv-U FTP Server - CVE-2026-28313

Published: July 27, 2026


Vulnerability identifier: #VU139624
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2026-28313
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: SolarWinds
Affected software:
Serv-U FTP Server

Detailed vulnerability description

The vulnerability allows a remote user to take over arbitrary accounts.

The vulnerability exists due to an insecure direct object reference in the smtp-related account access controls when handling crafted object references. A remote privileged user can manipulate direct object references to take over arbitrary accounts.

The issue can lead to SMTP hijacking, and the impact is lower in Windows deployments.


How to mitigate CVE-2026-28313

Install security update from vendor's website.

Sources