Command Injection in Froxlor Hosting Panel Affects Multiple Versions
CVE-2026-100714

9.4CRITICAL

Key Information:

Vendor

Froxlor

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100714?

Froxlor versions prior to 2.3.12 contain a command injection vulnerability affecting the system.letsencryptchallengepath setting, which lacks proper restriction or escaping mechanisms. Unlike other settings hardened in GHSA-33mp, this specific field is concatenated directly into the acme.sh command line without safeguards. As a result, an administrator or an actor with write access to the settings can inject arbitrary options into the acme.sh command, leading to potential command execution as root when the Let's Encrypt cron job is executed. This vulnerability allows attackers to manipulate the scheduling of tasks, leading to unauthorized file writes and other critical actions on the system. It is imperative to upgrade to version 2.3.12 or later to mitigate this risk.

Affected Version(s)

froxlor 0 < 2.3.12

froxlor 2.3.12

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

skeletonsec
.