AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2011-1526

MEDIUM · CVSS 6.5 EPSS 3.94%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2011-07-11 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 6.5. It may be remotely exploitable. Exploitation may require the attacker to be authenticated.

CVE
CVE-2011-1526
Severity
MEDIUM
CVSS
6.5
EPSS
3.94%

Original NVD Description

ftpd.c in the GSS-API FTP daemon in MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.1 and earlier does not check the krb5_setegid return value, which allows remote authenticated users to bypass intended group access restrictions, and create, overwrite, delete, or read files, via standard FTP commands, related to missing autoconf tests in a configure script.