Improper Neutralization of Special Elements in Output Used by a Downstream Component in Froxlor - CVE-2026-30932

 

Improper Neutralization of Special Elements in Output Used by a Downstream Component in Froxlor - CVE-2026-30932

Published: April 27, 2026


Vulnerability identifier: #VU128194
CSH Severity: Medium
CVSS v4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-30932
CWE-ID: CWE-74
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to inject arbitrary DNS records, disclose sensitive information, and cause a denial of service.

The vulnerability exists due to improper neutralization of special elements in output used by a downstream component in the DomainZones.add API endpoint and BIND zone file generation when processing unsanitized DNS record content for LOC, RP, SSHFP, and TLSA records. A remote user can submit crafted DNS record content containing newline characters and BIND directives to inject arbitrary DNS records, disclose sensitive information, and cause a denial of service.

Exploitation requires DNS management to be enabled for the customer account, and the injected content is written to disk when the DNS rebuild cron job runs.


Affected software

Froxlor

How to mitigate CVE-2026-30932

Install security update from vendor's website.

Froxlor - update to 2.3.5

External References

Related Security Bulletins