VYPR
patchPublished Sep 26, 2026· Updated Sep 28, 2026· 1 source

Froxlor: Thirteen Vulnerabilities Including Critical Flaws Disclosed Together

Key findings • Thirteen vulnerabilities disclosed simultaneously for Froxlor server administration panel. • Critical flaws include arbitrary file deletion, private key exposure, and incomplet…

Key findings

  • Thirteen vulnerabilities disclosed simultaneously for Froxlor server administration panel.
  • Critical flaws include arbitrary file deletion, private key exposure, and incomplete URL validation.
  • Stored XSS, credential disclosure, and session management vulnerabilities also present.
  • Patches available in Froxlor versions 2.3.11, 2.3.12, and 2.3.13.
  • Users urged to update immediately due to the severity and number of disclosed issues.

On September 26, 2026, a batch of thirteen vulnerabilities was disclosed for the Froxlor server administration panel, affecting versions up to 2.3.10, 2.3.11, or 2.3.12 depending on the specific vulnerability. These vulnerabilities, ranging in severity from medium to critical, were all disclosed on the same day, indicating a coordinated disclosure event. The issues span various components of Froxlor, including API command handling, cron tasks, and session management, posing significant risks to users if left unpatched.

Several critical vulnerabilities revolve around improper path and file handling. CVE-2026-100716, a critical vulnerability with a CVSS score of 9.6, stems from an off-by-one error in the Froxlor\FileDir::makeCorrectDir() function used in the customer data-export cron task. This flaw allows for arbitrary file deletion by failing to validate intermediate path components of the export destination. Similarly, CVE-2026-100708, a high-severity flaw (CVSS 7.1), involves the direct exposure of raw PEM TLS private-key content through API responses for certificates. Another critical issue, CVE-2026-100715 (CVSS 9.6), exploits symlink following in the FTP data deletion cron task, also due to improper path handling in FileDir::makeCorrectDir(). CVE-2026-100714 (CVSS 9.1) is a critical vulnerability where the system.letsencryptchallengepath setting is not properly restricted or escaped, allowing for potential command injection when constructing the acme.sh command. CVE-2026-100717 (CVSS 9.9) is a critical vulnerability related to URL validation, where carriage return and line feed characters are not properly handled in all URL components, and the userinfo component is never inspected.

Other significant vulnerabilities include stored cross-site scripting (XSS) and credential disclosure. CVE-2026-100720, a high-severity stored XSS vulnerability (CVSS 8.7), occurs when parsing the issuer organization from uploaded SSL certificates. CVE-2026-100719, a medium-severity flaw (CVSS 6.5), allows authenticated API users to retrieve bcrypt password hashes for protected-directory users via the DirProtections.listing API command, enabling offline cracking.

Security weaknesses in authentication and session management are also present. CVE-2026-100711 (CVSS 7.5) is a high-severity vulnerability where Froxlor fails to invalidate existing panel sessions, API keys, and two-factor authentication (2FA) trust cookies upon a user password change, allowing attackers to maintain access. CVE-2026-100712, a medium-severity issue (CVSS 6.5), allows for the immediate disabling of a user's 2FA via an unauthenticated GET request to the 2FA management page, lacking necessary confirmation or re-authentication. CVE-2026-100709 (CVSS 7.5) is a high-severity vulnerability where remembered-2FA tokens lack account namespace information, potentially allowing for cross-account authentication.

Additionally, CVE-2026-100718, a high-severity vulnerability (CVSS 7.1), involves an authenticated customer being able to bypass the mail.allow_external_domains policy in the EmailSender.add API command, even when external domains are explicitly disallowed. CVE-2026-100713 (CVSS 7.8) is a high-severity TOCTOU race condition in the SSH key synchronization cron job, where validation of symlinks occurs before the actual file operations. Finally, CVE-2026-100710 (CVSS 4.9) is a medium-severity vulnerability where sensitive columns, including DKIM private keys, are not filtered from API responses for domain information.

The Froxlor team has addressed these vulnerabilities in versions 2.3.11, 2.3.12, and 2.3.13. Users are strongly advised to update to the patched versions to mitigate these risks. The wide range of vulnerabilities, from critical file manipulation flaws to XSS and authentication bypasses, underscores the importance of timely patching for server administration panels like Froxlor.

The disclosure of these thirteen vulnerabilities on a single day highlights a significant security event for Froxlor users. The critical nature of several flaws, particularly those involving file deletion, arbitrary code execution potential, and private key exposure, demands immediate attention. The variety of issues, including XSS, credential exposure, and session hijacking vulnerabilities, indicates a broad impact across different functionalities of the Froxlor panel. Promptly updating to the patched versions is crucial for maintaining the security and integrity of servers managed by Froxlor.

The patched versions are:

Users should consult the official Froxlor advisories for detailed information on each vulnerability and the specific versions that contain fixes. Given the severity and number of vulnerabilities, a comprehensive review of security configurations and an immediate update are recommended.

Synthesized by Vypr AI