CVE-2026-41228Disclosure(froxlor / froxlor)

LOWCVSS 9.9 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Froxlor is open source server administration software. Prior to version 2.3.6, the Froxlor API endpoint `Customers.update` (and `Admins.update`) does not validate the `def_language` parameter against the list of available language files. An authenticated customer can set `def_language` to a path traversal payload (e.g., `../../../../../var/customers/webs/customer1/evil`), which is stored in the database. On subsequent requests, `Language::loadLanguage()` constructs a file path using this value and executes it via `require`, achieving arbitrary PHP code execution as the web server user. Version 2.3.6 fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-98

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • froxlor

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
froxlor

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-23: 3Technical Details · 2026-04-23: 204-23
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets2 URLs
Full discourse3 posts
  • CCB Alert@CCBalert
    Disclosure

    Warning: 2 critical vulnerabilities in #Froxlor. CVE-2026-41229 CVSS: 9.1 and CVE-2026-41228 CVSS: 10. Successful exploitation of CVE-2026-41228 can lead to remote code execution. #RCE! #Patch #Patch #Patch

    Post summary

    Tweet announces two critical vulnerabilities in Froxlor with CVE IDs and high CVSS scores, noting potential RCE but lacking patches, PoC, or exploit details.

    01000196
    7.2K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-41228 Froxlor is open source server administration software. Prior to version 2.3.6, the Froxlor API endpoint `Customers.update` (and `Admins.update`) does not validate the… https://www.cve.org/CVERecord?id=CVE-2026-41228

    Post summary

    The post references CVE-2026-41228 as a validation flaw in Froxlor's API but provides no details on exploitation, PoC, or remediation.

    0000069
    57.2K followersView on X
  • CTIWatch@ctiwatchcloud
    Disclosure

    🔍 Today's Top Vulnerabilities 🔴 CVE-2026-41679 | CVSS 10.0 🔴 CVE-2026-41228 | CVSS 9.9 🔴 CVE-2026-6235 | CVSS 9.8 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The tweet announces three new high‑severity CVEs with their CVSS scores and links to a website for details, but offers no PoC, exploit, patch, or indication of active exploitation.

    0000095
    5.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfroxlorfroxlor---

Explore more