Having the auth, db and file server in the same service.. an attacker doesn't even need lateral traversal or privilege escalation once inside..