By vendor
Proftpd vulnerabilities
Known CVEs affecting Proftpd products, prioritized by severity, with SEC.co remediation and detection guidance.
1 published vulnerability
- CVE-2026-35025HIGH 8.1
ProFTPD versions through 1.3.9b and 1.3.10rc2 contain a flaw that allows authenticated FTP users to bypass directory access controls. By manipulating file paths in rename commands using a /proc/self/root prefix, attackers can circumvent restrictions meant to prevent access to sensitive directories. The vulnerability enables them to rename files in restricted areas and then download those files, effectively gaining unauthorized access to protected content. Systems using ProFTPD's chroot feature (DefaultRoot) are protected from this issue.