CVE-2026-42167
ProFTPD ProFTPD, proftpd
mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL backend allows commands (e.g., COPY TO PROGRAM).
- CVSS
- 8.1
- EPSS
- 4.44% 90.4% percentile
- CISA KEV
- Not listed
- Published
- 2026.04.29