A critical SQL injection flaw in ProFTPD's mod_sql module, tracked as CVE-2026-42167, can let remote attackers manipulate database-backed FTP authentication and, in some deployments, achieve remote code execution. The bug affects ProFTPD versions before 1.3.10rc1 and stems from a logic error in is_escaped_text() that can misclassify attacker-controlled quoted input as already escaped when USER requests are logged through SQLNamedQuery expansions such as %U. Advisories and reporting say the weakness can be abused for authentication bypass, privilege escalation, data theft, and arbitrary code execution, with the issue classified as CWE-89 and assigned a CVSS 8.1 severity rating.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Public reporting summarized that CVE-2026-42167 can enable remote code execution in certain deployments, especially where SQL backends permit command execution features such as PostgreSQL COPY TO PROGRAM, and recommended upgrading to fixed ProFTPD releases or disabling mod_sql logging.
dCERT published advisory 2026-1276 warning that a ProFTPD vulnerability allows SQL injection, adding official advisory coverage for the issue.
ZeroPath published analysis describing how a logic error in ProFTPD's is_escaped_text() handling of quoted input can let attacker-controlled values reach SQL queries via logging variables such as %U, enabling severe impact depending on backend configuration.
MITRE received CVE-2026-42167 on 2026-04-28 for an SQL injection vulnerability in ProFTPD's mod_sql component that can lead to authentication bypass, privilege escalation, data theft, and in some configurations remote code execution.
An oss-sec post publicly highlighted CVE-2026-42167 in ProFTPD's mod_sql extension, describing SQL injection risks that could lead to authentication bypass, privilege escalation, database manipulation, or remote code execution depending on configuration. The post said the issue was fixed by a specific commit and addressed in ProFTPD 1.3.9a, with 1.3.10rc1 also reportedly containing the fix.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcedcert.de
Open sourcezeropath.com
Open sourcecvefeed.io
Open sourcebugflation.com
Open sourceseclists.org
Open sourceseclists.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.