Improper Authentication in Froxlor - CVE-2026-100709
Published: September 7, 2026 / Updated: September 28, 2026
Vulnerability details
The vulnerability allows a remote user to bypass administrator two-factor authentication and gain unauthorized administrator access.
The vulnerability exists due to improper authentication in remembered-2FA token validation when handling administrator login attempts. A remote user can submit a valid remembered-2FA token from a customer account with a colliding numeric ID and the target administrator's correct password to bypass administrator two-factor authentication and gain unauthorized administrator access.