Insufficient Session Expiration in Froxlor - CVE-2026-100711

 

Insufficient Session Expiration in Froxlor - CVE-2026-100711

Published: September 7, 2026 / Updated: September 28, 2026


Vulnerability identifier: #VU147270
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-100711
CWE-ID: CWE-613
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to retain access to an account after its password is changed.

The vulnerability exists due to insufficient session expiration in the password-update paths when an account password is changed. A remote user can reuse a previously obtained panel session, API key, or 2FA trust cookie to retain access to the account after its password is changed.

The issue affects both customer and administrator accounts.


Affected software

Froxlor

How to mitigate CVE-2026-100711

Install security update from vendor's website.

Froxlor - update to 2.3.12

External References

Related Security Bulletins