EIP-2026-114772
PRE-CVEProFTPd 1.3.0 (OpenSUSE) - 'mod_ctrls' Local Stack Overflow
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-114772. PoCs published by Michael Domberg.
AI-analyzed exploit summary This exploit targets a stack overflow vulnerability in ProFTPd's mod_ctrls module by sending a maliciously crafted buffer to a Unix domain socket, leading to remote code execution. The payload includes shellcode that binds a shell to port 19091.
Description
ProFTPd 1.3.0 (OpenSUSE) - 'mod_ctrls' Local Stack Overflow
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Michael Domberg · perllocalunix
https://www.exploit-db.com/exploits/10044
This exploit targets a stack overflow vulnerability in ProFTPd's mod_ctrls module by sending a maliciously crafted buffer to a Unix domain socket, leading to remote code execution. The payload includes shellcode that binds a shell to port 19091.
Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target:
ProFTPd with mod_ctrls (OpenSuSE 10.2 on i686)
No auth needed
Prerequisites:
Access to the Unix domain socket path · ProFTPd with mod_ctrls enabled
devstral-2 · analyzed Feb 16, 2026
Full analysis →
Details
Status
pre_cve
Tracked Since
Feb 18, 2026