logo

ProFTPD SQL Injection Flaw Enables Remote Code Execution

ID: 421666a4-e005-5577-9362-8551c9ff3d41

STIX ID: report--421666a4-e005-5577-9362-8551c9ff3d41

Feed Name: Cyber Press

Threat Score
84/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: Lucas Martin

...
...

A critical pre-authentication SQL injection (CVE-2026-42167) in ProFTPD's mod_sql can allow attackers to inject SQL via crafted USER names in logging queries, enabling remote code execution (when the SQL backend runs with excessive privileges), authentication bypass (creation of backdoor users), privilege escalation (setting home to /), and credential exfiltration; the flaw has a CVSSv3 score of 8.1, affects many default deployments and hosting control panels, public proof-of-concepts exist, and ProFTPD 1.3.9a (released 2026-04-27) contains the official fix.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.