CVE-2026-35025

HIGH

ProFTPD ACL Bypass via /proc/self/root Path Prefix in RNFR

Title source: cna
STIX 2.1

Description

ProFTPD through 1.3.9b and 1.3.10rc2 contains an access control bypass vulnerability that allows authenticated FTP users to circumvent Directory ACL restrictions by prefixing paths with /proc/self/root in the RNFR command handler. Attackers can exploit the unresolved symlink components in dir_canonical_path() to cause dir_check() to perform lexical path comparisons that match no configured Directory block, enabling rename operations on files in DenyAll-protected directories and subsequent retrieval of those files. Mitigation: Sessions configured with DefaultRoot (chroot) are not affected, as chroot changes the directory to which /proc/self/root resolves.

References (3)

Core 3
Core References
Technical Description technical-description
https://github.com/proftpd/proftpd/issues/2170
Product product
http://www.proftpd.org/

Scores

CVSS v3 8.1
EPSS 0.0035
EPSS Percentile 27.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-59
Status published
Products (4)
proftpd/proftpd 1.3.10 rc1 (2 CPE variants)
proftpd/proftpd < 1.3.9b
ProFTPD Project/ProFTPD < 1.3.10rc2
ProFTPD Project/ProFTPD < 1.3.9b
Published Jun 24, 2026
Tracked Since Jun 24, 2026