PT-2026-35642 · Proftpd · Proftpd

·

CVE-2026-42167

·

Published

2026-04-27

·

Updated

2026-07-23

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ProFTPD versions prior to 1.3.10rc1
Description A flaw in the mod sql module occurs due to insufficient protection of the SQL query structure. Remote attackers can execute arbitrary code by providing a specially crafted username in scenarios where USER requests are logged using expansions such as %U, provided the SQL backend supports commands like COPY TO PROGRAM. This issue can also lead to authentication bypass.
Recommendations Update to version 1.3.10rc1. As a temporary mitigation, restrict the use of the mod sql module or disable logging of USER requests using the %U expansion.

Exploit

Fix

LPE

RCE

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-06120
CVE-2026-42167
OESA-2026-2158
OESA-2026-2159
OESA-2026-2264
OESA-2026-2266
OESA-2026-2760
OPENSUSE-SU-2026:11352-1
PROFTPDCVE_2026_42167

Affected Products

Proftpd