Improper access control in Serv-U FTP Server - CVE-2026-28309
Published: July 27, 2026
Serv-U FTP Server
Detailed vulnerability description
The vulnerability allows a remote user to escalate privileges by creating system administrator accounts.
The vulnerability exists due to improper access control in Serv-U when handling administrative account management actions. A remote privileged user can create system administrator accounts to escalate privileges.
The impact is lower in Windows deployments.