ProFTPD mod_sql Flaw CVE-2026-42167 Gets Public PoC; RCE Depends on Config
A public proof-of-concept exploit for CVE-2026-42167, a SQL injection vulnerability in ProFTPD's mod_sql extension, was published on Exploit-DB (EDB-ID 52658) on August 25, 2026. The flaw carries a CVSS v3.1 score of 8.1 and affects ProFTPD installations where mod_sql is configured for SQL-backed authentication or SQL logging that incorporates user-controlled input. Exploitation is post-authentication and, depending on server configuration, can lead to authentication bypass, privilege escalation, or remote code execution via a PostgreSQL backend with elevated database privileges. ProFTPD version 1.3.9a has been identified as the patched release that addresses the vulnerability. Security researchers caution that the existence of a working PoC does not mean every ProFTPD deployment is at risk, as exploitability is directly tied to how mod_sql is configured on a given system.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in