CVE-2026-6265 PUBLISHED

Local Privilege Escalation in Cerberus FTP Server =< 2025.4.2

Assigner: NCSC-FI
Reserved: 14.04.2026 Published: 27.04.2026 Updated: 27.04.2026

Insecure preserved inherited permissions vulnerability in Cerberus FTP Server on Windows allows Privilege Escalation.This issue has been resolved in Cerberus FTP Server: 2026.1

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS Score: 7.3

Product Status

Vendor Cerberus
Product Cerberus FTP Server
Versions Default: unaffected
  • affected from 0 to 2025.4.2 (incl.)
  • Version 2026.1 is unaffected

Credits

  • Sharan Patil with Reversec finder

References

Problem Types

  • CWE-278 Insecure preserved inherited permissions CWE

Impacts

  • CAPEC-233 Privilege Escalation