Link following in Froxlor - CVE-2026-100716
Published: September 7, 2026 / Updated: September 28, 2026
Vulnerability details
The vulnerability allows a remote user to gain ownership of arbitrary root-owned directory trees.
The vulnerability exists due to improper link resolution before file access in the DataDump export cron when processing scheduled export destinations containing intermediate symlinks. A remote user can replace an intermediate export destination path component with a symlink to cause the root cron to recursively change ownership of an arbitrary directory tree.
The export feature must be enabled. Exploitation is deterministic and does not require a race condition.