PT-2026-51789 · Proftpd · Proftpd
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ProFTPD versions 1.3.9b through 1.3.10rc2
Description
An access control bypass allows authenticated FTP users to circumvent Directory ACL restrictions. By prefixing paths with
/proc/self/root in the RNFR command handler, attackers can exploit unresolved symlink components in the dir canonical path() function. This causes the dir check() function to perform lexical path comparisons that do not match any configured Directory block, enabling rename operations on files in DenyAll-protected directories and the subsequent retrieval of those files. Approximately 3.8 million instances are identified globally.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Configure sessions with DefaultRoot (chroot) to prevent the bypass, as this changes the directory to which
/proc/self/root resolves.Exploit
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Proftpd