Improper Neutralization of Argument Delimiters in a Command in Froxlor - CVE-2026-100714
Published: September 7, 2026 / Updated: September 28, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary commands as root.
The vulnerability exists due to improper neutralization of argument delimiters in the system.letsencryptchallengepath setting when its value is incorporated into the root cron's acme.sh command line. A remote privileged user can set a crafted challenge path to inject acme.sh hook arguments to execute arbitrary commands as root.
Exploitation occurs when the next Let's Encrypt cron job runs.