Improper Access Control in ProFTPD (CVE‑2015‑3306) Enables Remote File Read/Write
ProFTPD versions before 1.3.5a allow unauthenticated attackers to read or overwrite arbitrary files via FTP commands. The flaw underscores the need for auditable access‑control evidence and continuous monitoring to satisfy trust‑focused compliance reviews.
ADTP Breach Watch· October 8, 2026· CISA KEV
SeverityHigh
Type👤 Vulnerability
ConfidenceHigh
ReportedOct 8, 2026
Technology & SaaSorganizations that run ProFTPD for file transfer servicesVulnerability Exploit
What happened
A flaw in the `site cpfr` and `site cpto` commands lets remote attackers bypass normal access checks and read or write any file the FTP process can access. The issue is publicly disclosed with a CVSS v3.1 score of 7.5 (High).
Why it matters for trust and compliance
The incident highlights the importance of maintaining verifiable access‑control configurations and logging, which are key control objectives across frameworks such as NIST CSF 2.0.
Demonstrates the need for continuous evidence that file‑system permissions and service configurations align with policy.
Provides a concrete audit‑ready control point for reviewers demanding proof of proper access‑control enforcement.
Who is affected
organizations that run ProFTPD for file transfer services
Recommended actions
Upgrade to ProFTPD 1.3.5a or later and verify the patch is applied.
Disable or restrict the vulnerable FTP commands if not required.
Enforce least‑privilege file permissions for the FTP service account.
Enable detailed command logging and feed logs into a SIEM for continuous monitoring.
Document the remediation steps in a Trust Center to provide defensible evidence for auditors.
Details
Organizations
ProFTPD
CVEs
CVE-2015-3306
Get the Breach Digest
The incidents that matter for your vendors and your data, analysed for practitioners, in one email.