Command Injection in Froxlor Hosting Panel Affects Multiple Versions
CVE-2026-100714
What is CVE-2026-100714?
Froxlor versions prior to 2.3.12 contain a command injection vulnerability affecting the system.letsencryptchallengepath setting, which lacks proper restriction or escaping mechanisms. Unlike other settings hardened in GHSA-33mp, this specific field is concatenated directly into the acme.sh command line without safeguards. As a result, an administrator or an actor with write access to the settings can inject arbitrary options into the acme.sh command, leading to potential command execution as root when the Let's Encrypt cron job is executed. This vulnerability allows attackers to manipulate the scheduling of tasks, leading to unauthorized file writes and other critical actions on the system. It is imperative to upgrade to version 2.3.12 or later to mitigate this risk.
Affected Version(s)
froxlor 0 < 2.3.12
froxlor 2.3.12
