CVE-2026-35025
Last modified
CVE-2026-35025 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. ProFTPD through 1.3.9b and 1.3.10rc2 contains an access control bypass vulnerability that allows authenticated FTP users to circumvent Directory ACL restrictions by prefixing paths with /proc/self/root in the RNFR command handler. Attackers can exploit the unresolved symlink components in dir_canonical_path() to cause dir_check() to perform lexical path comparisons that match no configured Directory block, enabling rename operations on files in DenyAll-protected directories and subsequent retrieval of those files. EPSS estimates a 0.33% chance of exploitation in the next 30 days.
Description
ProFTPD through 1.3.9b and 1.3.10rc2 contains an access control bypass vulnerability that allows authenticated FTP users to circumvent Directory ACL restrictions by prefixing paths with /proc/self/root in the RNFR command handler. Attackers can exploit the unresolved symlink components in dir_canonical_path() to cause dir_check() to perform lexical path comparisons that match no configured Directory block, enabling rename operations on files in DenyAll-protected directories and subsequent retrieval of those files. Mitigation: Sessions configured with DefaultRoot (chroot) are not affected, as chroot changes the directory to which /proc/self/root resolves.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Proftpd | Proftpd | <= 1.3.9b | — |
| Proftpd | Proftpd | 1.3.10 | Rc1 |
References
- http://www.proftpd.org/Product, Release Notes
- https://github.com/proftpd/proftpd/issues/2170Issue Tracking, Mitigation
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-35025?
How severe is CVE-2026-35025?
How do I fix CVE-2026-35025?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-35019NetComm NF20MESH routers running firmware R6B031 and earlier…9.2
- CVE-2026-3502TrueConf Client downloads application update code and applie…7.8
- CVE-2026-35020Rejected reason: This CVE ID has been rejected by the its CV…
- CVE-2026-35021Rejected reason: This CVE ID has been rejected by its CVE Nu…
- CVE-2026-35022Rejected reason: This CVE ID has been rejected by its CVE Nu…
- CVE-2026-35023Wimi Teamwork On-Premises versions prior to 8.2.0 contain an…5.3
- CVE-2026-35026Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-35027Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-35028Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-35029LiteLLM is a proxy server (AI Gateway) to call LLM APIs in O…8.8
- CVE-2026-3503Protection mechanism failure in wolfCrypt post-quantum imple…5.2
- CVE-2026-35030LiteLLM is a proxy server (AI Gateway) to call LLM APIs in O…9.4
Are you affected by CVE-2026-35025?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
