ProFTPD mod_sql - Preauth User Backdoor
CVE-2026-42167
Verified
Description
ProFTPD mod_sql before 1.3.10rc1 contains a remote code execution caused by unsafe username handling with SQL backend commands in USER request logging expansions, letting remote attackers execute arbitrary code, exploit requires SQL backend allowing commands.
Severity
High
CVSS Score
9.8
Exploit Probability
7%
Affected Product
proftpd
Published Date
April 29, 2026
Template Author
pussycat0x
CVE-2026-42167.yaml
9.8Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-42167
CWE ID:
cwe-89
Remediation Steps
Upgrade to version 1.3.10rc1 or later.