PT-2026-51789 · Proftpd · Proftpd

·

CVE-2026-35025

·

Published

2026-06-24

·

Updated

2026-07-20

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ProFTPD versions 1.3.9b through 1.3.10rc2
Description An access control bypass allows authenticated FTP users to circumvent Directory ACL restrictions. By prefixing paths with /proc/self/root in the RNFR command handler, attackers can exploit unresolved symlink components in the dir canonical path() function. This causes the dir check() function to perform lexical path comparisons that do not match any configured Directory block, enabling rename operations on files in DenyAll-protected directories and the subsequent retrieval of those files. Approximately 3.8 million instances are identified globally.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Configure sessions with DefaultRoot (chroot) to prevent the bypass, as this changes the directory to which /proc/self/root resolves.

Exploit

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35025

Affected Products

Proftpd