SB2026090787 - Multiple vulnerabilities in Froxlor



SB2026090787 - Multiple vulnerabilities in Froxlor

Published: September 7, 2026 Updated: September 30, 2026

Security Bulletin ID SB2026090787
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 9
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 44% Low 56%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 9 vulnerabilities.


1) Improper Authentication (CVE-ID: CVE-2026-100709)

CWE-ID: CWE-287 - Improper Authentication

CVSSv4: 7.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to bypass administrator two-factor authentication and gain unauthorized administrator access.

The vulnerability exists due to improper authentication in remembered-2FA token validation when handling administrator login attempts. A remote user can submit a valid remembered-2FA token from a customer account with a colliding numeric ID and the target administrator's correct password to bypass administrator two-factor authentication and gain unauthorized administrator access.


2) Information disclosure (CVE-ID: CVE-2026-100710)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose DKIM private signing keys.

The vulnerability exists due to improperly filtered API responses in the Domains and SubDomains API commands when retrieving domain records through the JSON API. A remote privileged user can send a request for visible domain records to disclose DKIM private signing keys.

Exploitation requires the delegated customers_see_all flag.


3) Insufficient Session Expiration (CVE-ID: CVE-2026-100711)

CWE-ID: CWE-613 - Insufficient Session Expiration

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to retain access to an account after its password is changed.

The vulnerability exists due to insufficient session expiration in the password-update paths when an account password is changed. A remote user can reuse a previously obtained panel session, API key, or 2FA trust cookie to retain access to the account after its password is changed.

The issue affects both customer and administrator accounts.


4) Cross-site request forgery (CVE-ID: CVE-2026-100712)

CWE-ID: CWE-352 - Cross-Site Request Forgery (CSRF)

CVSSv4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disable two-factor authentication.

The vulnerability exists due to missing cross-site request forgery protection in the 2FA management handler when processing a cross-site GET request. A remote user can cause a logged-in user's browser to issue a crafted cross-site GET request to disable two-factor authentication.

The session cookie's SameSite=Lax setting is sent with cross-site top-level navigations.


5) Time-of-check Time-of-use (TOCTOU) Race Condition (CVE-ID: CVE-2026-100713)

CWE-ID: CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition

CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to escalate privileges.

The vulnerability exists due to a time-of-check to time-of-use race condition in the SSH-key synchronization cron when racing a symlink swap in the customer's home directory. A local user can swap the .ssh directory with a symlink to redirect the cron's write to root's authorized_keys file.

Customer shell access must be enabled through the system.allow_customer_shell setting.


6) Improper Neutralization of Argument Delimiters in a Command (CVE-ID: CVE-2026-100714)

CWE-ID: CWE-88 - Argument Injection or Modification

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to execute arbitrary commands as root.

The vulnerability exists due to improper neutralization of argument delimiters in the system.letsencryptchallengepath setting when its value is incorporated into the root cron's acme.sh command line. A remote privileged user can set a crafted challenge path to inject acme.sh hook arguments to execute arbitrary commands as root.

Exploitation occurs when the next Let's Encrypt cron job runs.


7) Link following (CVE-ID: CVE-2026-100715)

CWE-ID: CWE-59 - Improper Link Resolution Before File Access ('Link Following')

CVSSv4: 6.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to delete arbitrary directory trees.

The vulnerability exists due to improper link resolution before file access in the deleteFtpData cron task when processing a deletion task for an FTP account. A remote user can place a symlink in an FTP home directory to delete arbitrary directory trees.

The symlink must be planted after task creation and before cron execution.


8) Link following (CVE-ID: CVE-2026-100716)

CWE-ID: CWE-59 - Improper Link Resolution Before File Access ('Link Following')

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to gain ownership of arbitrary root-owned directory trees.

The vulnerability exists due to improper link resolution before file access in the DataDump export cron when processing scheduled export destinations containing intermediate symlinks. A remote user can replace an intermediate export destination path component with a symlink to cause the root cron to recursively change ownership of an arbitrary directory tree.

The export feature must be enabled. Exploitation is deterministic and does not require a race condition.


9) CRLF injection (CVE-ID: CVE-2026-100717)

CWE-ID: CWE-93 - Improper Neutralization of CRLF Sequences ('CRLF Injection')

CVSSv4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to inject arbitrary directives into web-server virtual-host configurations.

The vulnerability exists due to improper neutralization of CRLF sequences in Validate::validateUrl when processing a crafted subdomain redirect URL containing CRLF characters in the URL userinfo component. A remote user can submit a crafted redirect URL to inject arbitrary directives into web-server virtual-host configurations.

Exploitation requires subdomain-create rights and an available subdomain quota.


Remediation

Install update from vendor's website.