Authorization bypass through user-controlled key in Serv-U FTP Server - CVE-2026-28313
Published: July 27, 2026
Serv-U FTP Server
Detailed vulnerability description
The vulnerability allows a remote user to take over arbitrary accounts.
The vulnerability exists due to an insecure direct object reference in the smtp-related account access controls when handling crafted object references. A remote privileged user can manipulate direct object references to take over arbitrary accounts.
The issue can lead to SMTP hijacking, and the impact is lower in Windows deployments.