High severity8.1NVD Advisory· Published Apr 28, 2026· Updated Jul 24, 2026
CVE-2026-42167
CVE-2026-42167
Description
mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL backend allows commands (e.g., COPY TO PROGRAM).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4Patches
Vulnerability mechanics
References
6- github.com/proftpd/proftpd/issues/2052nvdExploitIssue TrackingPatch
- zeropath.com/blog/proftpd-cve-2026-42167-auth-bypass-privesc-rcenvdExploitPress/Media CoverageThird Party Advisory
- www.openwall.com/lists/oss-security/2026/05/01/13nvdMailing List
- www.openwall.com/lists/oss-security/2026/05/01/4nvdMailing List
- www.proftpd.org/docs/RELEASE_NOTES-1.3.10rc1nvdRelease Notes
- www.openwall.com/lists/oss-security/2026/05/01/4nvdMailing List
News mentions
1- ⚡ Weekly Recap: AI-Powered Phishing, Android Spying Tool, Linux Exploit, GitHub RCE & MoreThe Hacker News · May 4, 2026