High severity8.1NVD Advisory· Published Apr 28, 2026· Updated May 1, 2026
CVE-2026-42167
CVE-2026-42167
Description
mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL backend allows commands (e.g., COPY TO PROGRAM).
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- www.openwall.com/lists/oss-security/2026/05/01/13nvd
- www.openwall.com/lists/oss-security/2026/05/01/4nvd
- www.proftpd.org/docs/RELEASE_NOTES-1.3.10rc1nvd
- github.com/proftpd/proftpd/issues/2052nvd
- www.openwall.com/lists/oss-security/2026/05/01/4nvd
- zeropath.com/blog/proftpd-cve-2026-42167-auth-bypass-privesc-rcenvd
News mentions
1- ⚡ Weekly Recap: AI-Powered Phishing, Android Spying Tool, Linux Exploit, GitHub RCE & MoreThe Hacker News · May 4, 2026