Medium severity4.3NVD Advisory· Published Sep 14, 2026· Updated Sep 14, 2026
CVE-2026-90935
CVE-2026-90935
Description
Froxlor before 2.3.7 fails to validate the mysql_server parameter against a customer's allowed_mysqlserver allowlist in the Mysqls.add API command. Attackers can supply a disallowed server index to create MySQL databases and users on forbidden servers, bypassing per-customer access controls.
Affected products
2Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.