labs.reversec.comThird-party advisory
https://labs.reversec.com/advisories/2026/04/cerberus-ftp-server-elevation-of-privileges CVE-2026-6265
HIGH
Local Privilege Escalation in Cerberus FTP Server =< 2025.4.2
Record summary
CVE-2026-6265 has a selected CVSS score of 7.3 (high).
Description
Insecure preserved inherited permissions vulnerability in Cerberus FTP Server on Windows allows Privilege Escalation.This issue has been resolved in Cerberus FTP Server: 2026.1
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 27, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Cerberus FTP ServerBrowse Cerberus / Cerberus FTP ServerDefault status: unaffected | CVE List | Through 2025.4.2 | affected |
| 2026.1 | unaffected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-6265 cerberusftp.comrelease notes
https://www.cerberusftp.com/releasenotes