CVE-2026-42167: ProFTPD mod_sql RCE and How to Analyze the Exploit-DB PoC
A public PoC for CVE-2026-42167 in the mod_sql extension of the ProFTPD server, with a CVSS score of 8.1, has been published on Exploit-DB. The exploit demonstrates a path from SQL injection to RCE after authentication when using PostgreSQL; the fix is ProFTPD 1.3.9a.
- CVE-2026-42167 in ProFTPD mod_sql has CVSS 8.1
- PoC published on Exploit-DB as EDB-ID 52658 on August 25, 2026
- Exploitation requires authentication and powerful PostgreSQL privileges
- Vulnerability fixed in ProFTPD 1.3.9a
Read next
Security