Authorization bypass through user-controlled key in Serv-U FTP Server - CVE-2026-28316
Published: July 21, 2026 / Updated: July 27, 2026
Vulnerability details
The vulnerability allows a remote user to escalate privileges and execute commands as the root user.
The vulnerability exists due to insecure direct object reference in Serv-U when handling administrative object references. A remote user can access crafted object references to escalate privileges and execute commands as the root user.
This issue requires a domain account with administrator access. The impact is lower in Windows deployments.