https://seclists.org/oss-sec/2026/q2/310: CVE-2026-42167: SQL injection in ProFTPd prior to 1.3.9a
Published May 1, 2026
·Updated
Affected Software
1 affected component
ProFTPD ProFTPD<1.3.9a
Frequently Asked Questions
1
What is the severity of CVE-2026-42167?
CVE-2026-42167 is a critical severity SQL injection vulnerability in ProFTPd.
2
How do I fix CVE-2026-42167?
To mitigate CVE-2026-42167, upgrade ProFTPd to version 1.3.9a or later.
3
What versions of ProFTPd are affected by CVE-2026-42167?
ProFTPd versions prior to 1.3.9a are affected by CVE-2026-42167.
4
What is the impact of exploiting CVE-2026-42167?
Exploitation of CVE-2026-42167 can lead to unauthorized access and potential data breaches.
5
Does CVE-2026-42167 require specific configurations to be exploitable?
Yes, CVE-2026-42167 requires the use of mod_sql to be exploitable.