CVE-2026-41229Disclosure(froxlor / froxlor)

LOWCVSS 9.1 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Froxlor is open source server administration software. Prior to version 2.3.6, `PhpHelper::parseArrayToString()` writes string values into single-quoted PHP string literals without escaping single quotes. When an admin with `change_serversettings` permission adds or updates a MySQL server via the API, the `privileged_user` parameter (which has no input validation) is written unescaped into `lib/userdata.inc.php`. Since this file is `require`d on every request via `Database::getDB()`, an attacker can inject arbitrary PHP code that executes as the web server user on every subsequent page load. Version 2.3.6 contains a patch.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • froxlor

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
froxlor

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-23: 2Technical Details · 2026-04-23: 204-23
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • CCB Alert@CCBalert
    Disclosure

    Warning: 2 critical vulnerabilities in #Froxlor. CVE-2026-41229 CVSS: 9.1 and CVE-2026-41228 CVSS: 10. Successful exploitation of CVE-2026-41228 can lead to remote code execution. #RCE! #Patch #Patch #Patch

    Post summary

    The post warns of two critical Froxlor vulnerabilities with high CVSS scores and remote code execution potential, but provides no PoC, exploit, or patch details.

    01000196
    7.2K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41229 Froxlor is open source server administration software. Prior to version 2.3.6, `PhpHelper::parseArrayToString()` writes string values into single-quoted PHP string li… https://www.cve.org/CVERecord?id=CVE-2026-41229

    Post summary

    The post announces CVE‑2026‑41229 for Froxlor, highlighting a PHP string handling issue in `PhpHelper::parseArrayToString()` prior to v2.3.6, but it lacks evidence of PoC, exploits, or mitigation details.

    0000069
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfroxlorfroxlor---

Explore more