Information disclosure in Froxlor - CVE-2026-100710
Published: September 7, 2026 / Updated: September 28, 2026
Vulnerability details
The vulnerability allows a remote user to disclose DKIM private signing keys.
The vulnerability exists due to improperly filtered API responses in the Domains and SubDomains API commands when retrieving domain records through the JSON API. A remote privileged user can send a request for visible domain records to disclose DKIM private signing keys.
Exploitation requires the delegated customers_see_all flag.