Arbitrary File Deletion Vulnerability in Froxlor by Froxlor Team
CVE-2026-100715

8.5HIGH

Key Information:

Vendor

Froxlor

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100715?

Froxlor versions up to 2.3.10 possess a vulnerability allowing arbitrary file deletion through symlink manipulation, particularly within the FTP data deletion cron task. When an FTP account is removed, a cron job is scheduled, which incorrectly handles directory paths by skipping necessary symlink checks. This flaw allows authenticated users to create symlinks that lead to the execution of 'rm -rf' commands with root privileges, enabling them to delete arbitrary directory trees. This poses severe risks of cross-tenant data destruction and potential denial of service on the host system. The issue has been resolved in Froxlor version 2.3.12.

Affected Version(s)

froxlor 0 < 2.3.12

froxlor 2.3.12

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

skeletonsec
.