https://seclists.org/oss-sec/2026/q2/319: CVE-2026-42167: SQL injection in ProFTPd prior to 1.3.9a
Published May 1, 2026
·Updated
Affected Software
1 affected component
ProFTPD ProFTPD<1.3.9a
Frequently Asked Questions
1
What is the severity of CVE-2026-42167?
CVE-2026-42167 is classified as a high-severity SQL injection vulnerability in ProFTPd.
2
How do I fix CVE-2026-42167?
To fix CVE-2026-42167, upgrade to ProFTPd version 1.3.9a or later.
3
What is the impact of CVE-2026-42167?
The impact of CVE-2026-42167 allows an attacker to execute arbitrary SQL commands through specific exploits.
4
Is CVE-2026-42167 present in all versions of ProFTPd?
CVE-2026-42167 affects all versions of ProFTPd prior to 1.3.9a.
5
How can I determine if my ProFTPd installation is vulnerable to CVE-2026-42167?
You can determine vulnerability by checking the version of your installed ProFTPd against the fixed version 1.3.9a.