CVE-2026-42167

HIGH NUCLEI LAB

ProFTPD <1.3.10rc1 - RCE

Title source: llm
STIX 2.1

Description

mod_sql in ProFTPD before 1.3.10rc1 allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL backend allows commands (e.g., COPY TO PROGRAM).

Exploits (3)

github WORKING POC
by Sl4cK0TH · pythonpoc
https://github.com/Sl4cK0TH/CVE-2026-42167-PoC
github WORKING POC
by dinosn · pythonpoc
https://github.com/dinosn/proftpd-CVE-2026-42167-analysis
nomisec WORKING POC
by ZeroPathAI · poc
https://github.com/ZeroPathAI/proftpd-CVE-2026-42167-poc

Nuclei Templates (1)

ProFTPD mod_sql - Preauth User Backdoor
HIGHVERIFIEDby pussycat0x
Shodan: 220 ProFTPD

Scores

CVSS v3 8.1
EPSS 0.1239
EPSS Percentile 93.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-89
Status published
Products (2)
ProFTPD/ProFTPD 1.3.7b - 1.3.10rc1
ProFTPD/ProFTPD 1.3.7b - 1.3.9a
Published Apr 28, 2026
Tracked Since Apr 29, 2026