What is CVE-2026-67193?
Xlight FTP Server versions before 3.9.5 contain an information disclosure vulnerability where unauthenticated attackers can obtain the server's `GetTickCount()` value by sending a USER command with a username ending in `:adm` suffix. Upgrading to version 3.9.5 or later is recommended.
Azərbaycanca: Xlight FTP Server-in 3.9.5-dən əvvəlki versiyalarında məlumat sızması zəifliyi mövcuddur. Təcavüzkar `:adm` suffix-i ilə USER əmri göndərərək autentifikasiya olmadan serverin `GetTickCount()` dəyərini əldə edə bilir. Serveri 3.9.5 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which versions of Xlight FTP Server are affected by CVE-2026-67193?
Xlight FTP Server versions before 3.9.5 are affected. Upgrading to version 3.9.5 or later is recommended.
What information can an attacker obtain by exploiting CVE-2026-67193?
An unauthenticated attacker can obtain the server's `GetTickCount()` value by sending a USER command with a username ending in `:adm` suffix.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.