Private Key Disclosure in Froxlor Affected Versions
CVE-2026-100708

7.1HIGH

Key Information:

Vendor

Froxlor

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100708?

Froxlor, prior to version 2.3.13, contains a vulnerability where the ssl_key_file column, which holds raw PEM TLS private-key content, is returned without proper access controls in the responses of the Certificates.get and Certificates.listing API commands. As a result, low-privileged authenticated users can access their own domain's private keys, including those generated by Let's Encrypt. Moreover, accounts with reseller privileges or broad visibility can access the private keys of other users, enabling potential threats such as domain impersonation and active machine-in-the-middle attacks. This significant oversight could lead to severe security ramifications for affected users.

Affected Version(s)

froxlor 0 < 2.3.13

froxlor 2.3.13

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

manus-use
.