CVE-2026-42167 allows auth bypass, privesc and code execution in ProFTPD

CVE-2026-42167 has been reserved by MITRE to track an authentication bypass, privilege escalation, and code execution vulnerability in ProFTPD. The ProFTPD project has made the flaw public and is rolling out a release to address it. Full technical details and POCs will follow.

Research

1 min read

John Walker
John Walker

2026-04-27

CVE-2026-42167 allows auth bypass, privesc and code execution in ProFTPD

Summary

CVE-2026-42167 has been reserved by MITRE to track this issue. The ProFTPD project has made the flaw public and is rolling out a release to address it. We'll update this blog with full technical details and POCs as soon as it's responsible to do so!

Detect & fix
what others miss

Security magnifying glass visualization