/Vulnerability Library

ProFTPD mod_sql - Preauth User Backdoor

CVE-2026-42167
Verified

Description

ProFTPD mod_sql before 1.3.10rc1 contains a remote code execution caused by unsafe username handling with SQL backend commands in USER request logging expansions, letting remote attackers execute arbitrary code, exploit requires SQL backend allowing commands.

Severity

High

CVSS Score

9.8

Exploit Probability

7%

Affected Product

proftpd

Published Date

April 29, 2026

Template Author

pussycat0x

CVE-2026-42167.yaml
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-42167
CWE ID:
cwe-89

References

https://github.com/ZeroPathAI/proftpd-CVE-2026-42167-pochttps://zeropath.com/blog/proftpd-cve-2026-42167-auth-bypass-privesc-rce

Remediation Steps

Upgrade to version 1.3.10rc1 or later.