Authorization bypass through user-controlled key in Serv-U FTP Server - CVE-2026-28302

 

Authorization bypass through user-controlled key in Serv-U FTP Server - CVE-2026-28302

Published: July 21, 2026 / Updated: July 27, 2026


Vulnerability identifier: #VU139683
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-28302
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to escalate privileges and execute arbitrary code as root.

The vulnerability exists due to insecure direct object reference in Serv-U when handling administrative object references. A remote user can access crafted object references to escalate privileges and execute arbitrary code as root.

This issue requires group administrator access. The impact is lower in Windows deployments.


Affected software

Serv-U FTP Server

How to mitigate CVE-2026-28302

Install security update from vendor's website.

Serv-U FTP Server - update to 2026.3

External References

Related Security Bulletins