Improper access control in Serv-U FTP Server - CVE-2026-28310
Published: July 27, 2026
Serv-U FTP Server
Detailed vulnerability description
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper access control in user type management in Serv-U when handling administrative actions. A remote privileged user can elevate a domain administrator account to system administrator privileges to escalate privileges.
The impact is lower in Windows deployments.