CVE-2026-6265 Details
Description
Insecure preserved inherited permissions vulnerability in Cerberus FTP Server on Windows allows Privilege Escalation.This issue has been resolved in Cerberus FTP Server: 2026.1
A vulnerability allowing local privilege escalation has been identified in Cerberus FTP Server on Windows, affecting versions through 2025.4.2. The issue arises from insecure inherited permissions that allow low-privileged users to replace legitimate update files with malicious executables. When the update process is initiated, the malicious file is executed with administrative privileges, leading to unauthorized access.
Users should update Cerberus FTP Server to version 2026.1 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://labs.reversec.com/advisories/2026/04/cerberus-ftp-server-elevation-of-privileges | CISA-ADP | ExploitVendor Advisory |
| https://labs.reversec.com/advisories/2026/04/cerberus-ftp-server-elevation-of-privileges | National Cyber Security Centre Finland | ExploitVendor Advisory |
| https://www.cerberusftp.com/releasenotes/ | National Cyber Security Centre Finland | Release Notes |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-278 | Insecure Preserved Inherited Permissions | National Cyber Security Centre Finland |
Affected Products
| Product | Versions |
|---|---|
| cerberusftp ftp server | < 2026.1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | National Cyber Security Centre Finland |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 7, 2026 | Initial Analysis | [email protected] |
| Apr 27, 2026 | New CVE Received | National Cyber Security Centre Finland |
| Apr 27, 2026 | CVE Modified | CISA-ADP |