Insufficient Session Expiration in Froxlor - CVE-2026-100711
Published: September 7, 2026 / Updated: September 28, 2026
Vulnerability details
The vulnerability allows a remote user to retain access to an account after its password is changed.
The vulnerability exists due to insufficient session expiration in the password-update paths when an account password is changed. A remote user can reuse a previously obtained panel session, API key, or 2FA trust cookie to retain access to the account after its password is changed.
The issue affects both customer and administrator accounts.