Improper Neutralization of Argument Delimiters in a Command in Froxlor - CVE-2026-100714

 

Improper Neutralization of Argument Delimiters in a Command in Froxlor - CVE-2026-100714

Published: September 7, 2026 / Updated: September 28, 2026


Vulnerability identifier: #VU147273
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-100714
CWE-ID: CWE-88
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary commands as root.

The vulnerability exists due to improper neutralization of argument delimiters in the system.letsencryptchallengepath setting when its value is incorporated into the root cron's acme.sh command line. A remote privileged user can set a crafted challenge path to inject acme.sh hook arguments to execute arbitrary commands as root.

Exploitation occurs when the next Let's Encrypt cron job runs.


Affected software

Froxlor

How to mitigate CVE-2026-100714

Install security update from vendor's website.

Froxlor - update to 2.3.12

External References

Related Security Bulletins