CVE-2026-67193: Observable Discrepancy in Xlight Xlight FTP Server
Xlight FTP Server versions prior to 3.9.5 have an information disclosure vulnerability that allows unauthenticated attackers to obtain the server's current GetTickCount() value. This is achieved by sending a specially crafted USER command with a username ending in the :adm suffix, which triggers the admin protocol path and leaks timing information in the FTP 331 response. This vulnerability does not require authentication, separate ports, or configuration changes.
AI Analysis
Technical Summary
CVE-2026-67193 describes an information disclosure vulnerability in Xlight FTP Server before version 3.9.5. An unauthenticated attacker can send a USER command with a username ending in ':adm' to trigger the admin protocol path within the FTP listener before authentication completes. This causes the server to leak its current GetTickCount() value via the FTP 331 response, exposing timing information that could be used for further analysis or attacks. The vulnerability does not require additional ports or configuration changes to exploit.
Potential Impact
The vulnerability allows unauthenticated attackers to obtain timing information from the server, specifically the current GetTickCount() value. This constitutes an information disclosure that could potentially aid attackers in reconnaissance or timing-based attacks. There is no indication of direct code execution or privilege escalation from this vulnerability alone.
Mitigation Recommendations
No official patch or remediation is currently confirmed for this vulnerability. Users should monitor the vendor's advisory for updates. Until a fix is available, consider restricting access to the FTP service or implementing network-level controls to limit exposure. Avoid using usernames ending with ':adm' if possible, as this triggers the vulnerability.
CVE-2026-67193: Observable Discrepancy in Xlight Xlight FTP Server
Description
Xlight FTP Server versions prior to 3.9.5 have an information disclosure vulnerability that allows unauthenticated attackers to obtain the server's current GetTickCount() value. This is achieved by sending a specially crafted USER command with a username ending in the :adm suffix, which triggers the admin protocol path and leaks timing information in the FTP 331 response. This vulnerability does not require authentication, separate ports, or configuration changes.
CVSS v4.0
Score 6.9medium
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-67193 describes an information disclosure vulnerability in Xlight FTP Server before version 3.9.5. An unauthenticated attacker can send a USER command with a username ending in ':adm' to trigger the admin protocol path within the FTP listener before authentication completes. This causes the server to leak its current GetTickCount() value via the FTP 331 response, exposing timing information that could be used for further analysis or attacks. The vulnerability does not require additional ports or configuration changes to exploit.
Potential Impact
The vulnerability allows unauthenticated attackers to obtain timing information from the server, specifically the current GetTickCount() value. This constitutes an information disclosure that could potentially aid attackers in reconnaissance or timing-based attacks. There is no indication of direct code execution or privilege escalation from this vulnerability alone.
Mitigation Recommendations
No official patch or remediation is currently confirmed for this vulnerability. Users should monitor the vendor's advisory for updates. Until a fix is available, consider restricting access to the FTP service or implementing network-level controls to limit exposure. Avoid using usernames ending with ':adm' if possible, as this triggers the vulnerability.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-07-28T16:06:49.774Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a6a25599c2644c7f8bbd21e
Added to database: 07/29/2026, 16:07:53 UTC
Last enriched: 07/29/2026, 16:22:46 UTC
Last updated: 07/29/2026, 16:24:21 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.