Authorization bypass through user-controlled key in Serv-U FTP Server - CVE-2026-28302
Published: July 21, 2026 / Updated: July 27, 2026
Vulnerability details
The vulnerability allows a remote user to escalate privileges and execute arbitrary code as root.
The vulnerability exists due to insecure direct object reference in Serv-U when handling administrative object references. A remote user can access crafted object references to escalate privileges and execute arbitrary code as root.
This issue requires group administrator access. The impact is lower in Windows deployments.