CVE-2026-35025Disclosure(proftpd / proftpd)

LOWCVSS 8.6 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch proftpd proftpd systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

ProFTPD through 1.3.9b and 1.3.10rc2 contains an access control bypass vulnerability that allows authenticated FTP users to circumvent Directory ACL restrictions by prefixing paths with /proc/self/root in the RNFR command handler. Attackers can exploit the unresolved symlink components in dir_canonical_path() to cause dir_check() to perform lexical path comparisons that match no configured Directory block, enabling rename operations on files in DenyAll-protected directories and subsequent retrieval of those files. Mitigation: Sessions configured with DefaultRoot (chroot) are not affected, as chroot changes the directory to which /proc/self/root resolves.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-59

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • proftpd

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 8 signals
  • Disclosure: 8 classified signals
  • Peaked at 4 mentions on most recent observed day (2026-07-20)
  • 8 total mentions across 3 days

Affected systems

Vendors
Products
proftpd

1 version affected across 1 product

Deep dive

Activity timeline8 mentions / 3d
01234Mentions · 2026-07-01: 3Mentions · 2026-07-09: 1Mentions · 2026-07-20: 4Patch / Workaround · 2026-07-01: 1Technical Details · 2026-07-01: 3Technical Details · 2026-07-09: 1Technical Details · 2026-07-20: 407-0107-0907-20
Signal classification1 categories
Disclosure
8100.0%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-07-013
Disclosure3
2026-07-091
Disclosure1
2026-07-204
Disclosure4
Full discourse8 posts
  • ZoomEye@zoomeye_team
    Disclosure

    🚨 CVE-2026-35025: ProFTPD ACL Bypass via /proc/self/root Path Prefix in RNFR Critical Vulnerability Alert! ProFTPD is affected by CVE-2026-35025. Full Vulnerability Details & Analysis at DarkEye: 🔗 https://darkeye.org/vuln/cve/CVE-2026-35025 🔍 Identify Targets via ZoomEye: Filter: vul.cve="CVE-2026-35025" Search Dork: app="ProFTPD" Exposure: 3.8m instances identified globally. ZoomEye Search Link: 👉 https://www.zoomeye.ai/searchResult?q=YXBwPSJQcm9GVFBEIg==&t=all&utm_source=twitter&utm_medium=social&utm_campaign=cve_ops_20260701 #Infosec #CyberSecurity #ZoomEye #DarkEye

    Post summary

    The tweet announces CVE‑2026‑35025, a ProFTPD ACL bypass, with a link to DarkEye analysis and ZoomEye search, without indicating any PoC, exploit code, or active exploitation.

    111047184.2K
    12.7K followersView on X
  • Hunter@HunterMapping
    Disclosure

    🚨Alert🚨 CVE-2026-35025 : ProFTPD ACL Bypass via /proc/self/root Path Prefix in RNFR 📊 2.0M Services are found on the http://hunter.how yearly. 🧐Detail :https://github.com/proftpd/proftpd/issues/2170 🔗Hunter Link:https://hunter.how/list?searchValue=product.name%3D%22ProFTPD%22 👇Query HUNTER : http://product.name="ProFTPD" 📰Refer:https://www.vulncheck.com/advisories/proftpd-acl-bypass-via-proc-self-root-path-prefix-in-rnfr #hunterhow #infosec #infosecurity #OSINT #Vulnerability

    Post summary

    The post announces the discovery of CVE‑2026‑35025 with a technical description, but it does not provide a PoC, exploit, mitigation, or evidence of active exploitation.

    01002484.4K
    26.0K followersView on X
  • Daily CyberSecurity@the_yellow_fall
    Disclosure

    A ProFTPD ACL bypass (CVE-2026-35025, CVSS 8.6) lets logged-in FTP users reach files in restricted directories. No patch is out yet; use DefaultRoot. #ProFTPD #CVE202635025 #ACLBypass #FTP #CyberSecurity https://securityonline.info/proftpd-acl-bypass https://t.co/DYrxe1oaj4

    Post summary

    A newly disclosed ProFTPD ACL bypass (CVE-2026-35025) with CVSS 8.6 allows authenticated users to access restricted directories; no patch yet, workaround is to use DefaultRoot.

    01062740
    12.9K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Full Tweet 🚨 CVE-2026-35025: ProFTPD ACL Bypass via /proc/self/root Path Prefix in RNFR 0day Intel: 🚨 CVE-2026-35025: ProFTPD ACL Bypass via /proc/self/root Path Prefix in RNFR

    Post summary

    The tweet announces a newly announced CVE-2026-35025 affecting ProFTPD, describing it as a zero‑day ACL bypass but provides no exploit code, patch, or evidence of active exploitation.

    1000050
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Source: X search for CVE-2026 critical Posted: 2026-07-01T05:01:48.000Z Likes: 32 0day Intel: 🚨 CVE-2026-35025: ProFTPD ACL Bypass via /proc/self/root Path Prefix in RNFR

    Post summary

    The tweet announces a newly discovered CVE-2026-35025 in ProFTPD, detailing the ACL bypass flaw, but it provides no PoC, exploit tool, or patch information.

    1000045
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    0day Intel: 🚨 CVE-2026-35025: ProFTPD ACL Bypass via /proc/self/root Path Prefix in RNFR

    Post summary

    The post announces a newly disclosed ProFTPD ACL bypass vulnerability (CVE‑2026‑35025) with technical detail but no PoC, exploit, or patch information.

    1000039
    326 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-35025: 🚨 CVE-2026-35025: ProFTPD ACL Bypass via /proc/self/root Path Prefix in RNFR Critical Vulnerability Alert! ProFTPD is affected by CVE-2026-35025. Full Vulnerability Details & Analysis at DarkEye: 🔗 🔍 Identify Targets via…

    Post summary

    The post announces a ProFTPD vulnerability (CVE-2026-35025) with an ACL Bypass via /proc/self/root in RNFR, providing a link to detailed analysis but no PoC, exploit, patch, or exploitation evidence.

    1000049
    326 followersView on X
  • NCA Azerbaijan@NCAAzerbaijan
    Disclosure

    "ProFTPD FTP" serverində giriş nəzarətinin "bypass" edilməsi nəticəsində icazəsiz fayl əməliyyatları riski (CVE-2026-35025) aşkarlanıb. #MKA #NCA #MilliCERT #Cybersecurity #Kibertəhlükəsizlik #Xəbərdarlıq https://t.co/ygR57N600S

    Post summary

    A new authentication bypass vulnerability (CVE‑2026‑35025) was identified in ProFTPD, enabling unauthorized file operations.

    00010667
    136 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appproftpdproftpd---
Appproftpdproftpd1.3.10--
Appproftpdproftpd1.3.10--

Explore more