Private Key Disclosure in Froxlor Affected Versions
CVE-2026-100708
7.1HIGH
What is CVE-2026-100708?
Froxlor, prior to version 2.3.13, contains a vulnerability where the ssl_key_file column, which holds raw PEM TLS private-key content, is returned without proper access controls in the responses of the Certificates.get and Certificates.listing API commands. As a result, low-privileged authenticated users can access their own domain's private keys, including those generated by Let's Encrypt. Moreover, accounts with reseller privileges or broad visibility can access the private keys of other users, enabling potential threats such as domain impersonation and active machine-in-the-middle attacks. This significant oversight could lead to severe security ramifications for affected users.
Affected Version(s)
froxlor 0 < 2.3.13
froxlor 2.3.13
