Authorization bypass through user-controlled key in Serv-U FTP Server - CVE-2026-28317
Published: July 21, 2026 / Updated: July 27, 2026
Vulnerability details
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to insecure direct object reference in Serv-U when handling administrative object references. A remote user can access crafted object references to escalate privileges.
Domain administrator access is required. The impact is lower in Windows deployments.