Impact
Cerberus FTP Server contains an insecure permission handling flaw that allows local users to elevate privileges by exploiting incorrectly preserved inherited file permissions. The vulnerability can lead to unauthorized access to restricted files and configuration data, potentially compromising the integrity and confidentiality of the system. The flaw is based on CWE-278 – Insecure Permissions.
Affected Systems
All installations of Cerberus FTP Server up to and including version 2025.4.2 running on Windows are susceptible. The vulnerability has been fixed in version 2026.1 and later releases.
Risk and Exploitability
The CVSS score of 7.3 marks this as a high‑risk issue. EPSS data are not available, and it is not listed in the CISA KEV catalog, indicating no confirmed widespread exploitation to date. The likely attack vector is local; an attacker with local access can manipulate permissions to gain elevated rights. Although no public exploit is known, the severity and the nature of the flaw warrant immediate remediation.
OpenCVE Enrichment