Logo
vulnerabilityCVE-2026-35025
Name
CVE-2026-35025
Source
NVD ( link)Debian ( link)
Description
ProFTPD through 1.3.9b and 1.3.10rc2 contains an access control bypass vulnerability that allows authenticated FTP users to circumvent Directory ACL restrictions by prefixing paths with /proc/self/root in the RNFR command handler. Attackers can exploit the unresolved symlink components in dir_canonical_path() to cause dir_check() to perform lexical path comparisons that match no configured Directory block, enabling rename operations on files in DenyAll-protected directories and subsequent retrieval of those files. Mitigation: Sessions configured with DefaultRoot (chroot) are not affected, as chroot changes the directory to which /proc/self/root resolves.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
proftpd
Exploitable

Vulnerability Ratings#


8.6
CVSSv4
8.1
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
1.3.8d
Exploitable
buildroot
master
1.3.9a
Exploitable
yocto
kirkstone
1.3.7c
Exploitable
yocto
scarthgap
1.3.7f
Exploitable