Two-Factor Authentication Bypass in Froxlor by Froxlor
CVE-2026-100712
7.1HIGH
What is CVE-2026-100712?
Froxlor versions prior to 2.3.12 are susceptible to a vulnerability that allows unauthorized disabling of two-factor authentication. An unauthenticated GET request to the management page can exploit this flaw, leading to immediate deactivation of a user's 2FA without confirmation or necessary re-authentication. The limited scope of CSRF protection to only specific request types enables attackers to use crafted links to exploit logged-in users, undermining account security. This exposure potentially allows for account takeovers if combined with compromised passwords.
Affected Version(s)
froxlor 0 < 2.3.12
froxlor 2.3.12
