PT-2026-35642 · Proftpd · Proftpd

Valtteri Vuorikoski

·

Published

2026-04-27

·

Updated

2026-05-11

·

CVE-2026-42167

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ProFTPD versions prior to 1.3.10rc1
Description A flaw in the mod sql module allows unauthenticated remote attackers to bypass authentication and execute arbitrary code. The issue stems from a lack of protection for SQL query structures, specifically when logging USER requests using expansions such as %U. If the SQL backend supports command execution (for example, COPY TO PROGRAM), an attacker can use a crafted username to break SQL strings and execute OS-level commands. Over 162,000 internet-facing instances are estimated to be at risk.
Recommendations Update to version 1.3.10rc1.

Exploit

Fix

LPE

RCE

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2026-06120
CVE-2026-42167
OESA-2026-2158
OESA-2026-2159
OESA-2026-2264
OESA-2026-2266

Affected Products

Proftpd