CVE-2026-42167
HIGH 8.1EPSS 7.4%
mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL backend allows commands (e.g., COPY TO PROGRAM).
- CVSS v3.1
- 8.1 HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS
- 7.39% chance of exploitation in the next 30 days, 94th percentile
- Nuclei
- high · CWE-89
- Published
- 2026-04-28
- Updated
- 2026-05-01
Proof-of-concept exploits (7)
- ZeroPathAI/proftpd-CVE-2026-42167-poc24★ · 2026-04-29
- kaleth4/CVE-2026-421670★ · 2026-05-04
- efeanilarslan/CVE-2026-42167-Exploit0★ · 2026-05-02
- jimmexploit/CVE-2026-42167-PoC1★ · 2026-05-02
- Sl4cK0TH/CVE-2026-42167-PoC0★ · 2026-05-02
- SimoesCTT/CTT-ProFTPD-Resonance0★ · 2026-05-02
- dinosn/proftpd-CVE-2026-42167-analysis