CVE-2026-100716

LOWCVSS 9.4 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Froxlor is a server administration panel. In versions 2.3.10 and earlier, the customer data-export (DataDump) cron fails to validate intermediate path components of the export destination: Froxlor\FileDir::makeCorrectDir() contains an off-by-one in its path-component walk that skips the first segment below the customer home directory, and the guard in ExportCron.php checks only the final component with is_link(). An authenticated customer whose account has the export feature enabled can schedule an export into a genuine subdirectory of their own webspace, then replace an intermediate path component with a symlink before the root-owned cron runs. The cron's `chown -R` then recursively changes ownership of the linked directory tree — for example /etc — to the customer's UID, yielding host root and cross-tenant compromise. Exploitation is deterministic and requires no race. This is an incomplete fix of GHSA-75h4-... The issue is fixed in Froxlor 2.3.12.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-59

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 1 mentions (2026-09-26); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-09-26: 1Mentions · 2026-09-27: 109-2609-27
Referenced assets2 URLs
Full discourse2 posts
  • ThreatAft@ThreatAft

    🔐🚨 FROXLOR — 3 CVEs, 2 × CVSS 9.9 • CVE-2026-100716 — Symlink path traversal → chown /etc • CVE-2026-100717 — CRLF injection → nginx/Apache config → https://threataft.com/articles/froxlor-mass-disclosure-cve-2026-100716-100717-100715 #Froxlor #CVE #PathTraversal #PatchNow #CyberSecurity #ThreatIntel

    0000037
    44 followersView on X
  • CVE@CVEnew

    CVE-2026-100716 Froxlor is a server administration panel. In versions 2.3.10 and earlier, the customer data-export (DataDump) cron fails to validate intermediate path components of… https://www.cve.org/CVERecord?id=CVE-2026-100716

    000001.1K
    58.1K followersView on X

Explore more