Time-of-check Time-of-use (TOCTOU) Race Condition in Froxlor - CVE-2026-100713
Published: September 7, 2026 / Updated: September 28, 2026
Vulnerability details
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to a time-of-check to time-of-use race condition in the SSH-key synchronization cron when racing a symlink swap in the customer's home directory. A local user can swap the .ssh directory with a symlink to redirect the cron's write to root's authorized_keys file.
Customer shell access must be enabled through the system.allow_customer_shell setting.