Information disclosure in Froxlor - CVE-2026-100710

 

Information disclosure in Froxlor - CVE-2026-100710

Published: September 7, 2026 / Updated: September 28, 2026


Vulnerability identifier: #VU147269
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-100710
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose DKIM private signing keys.

The vulnerability exists due to improperly filtered API responses in the Domains and SubDomains API commands when retrieving domain records through the JSON API. A remote privileged user can send a request for visible domain records to disclose DKIM private signing keys.

Exploitation requires the delegated customers_see_all flag.


Affected software

Froxlor

How to mitigate CVE-2026-100710

Install security update from vendor's website.

Froxlor - update to 2.3.12

External References

Related Security Bulletins