Symlink Vulnerability in Froxlor Server Administration Panel
CVE-2026-100716
9.4CRITICAL
What is CVE-2026-100716?
Froxlor, a server administration panel, has a flaw in its data export feature where an authenticated customer can exploit symlink manipulation. In affected versions, the cron job for customer data export does not correctly validate path components, allowing users to create symbolic links that lead to unauthorized ownership changes of directory trees. This vulnerability can potentially compromise the host's root directory and impact multiple tenants' data integrity. The issue has been resolved in version 2.3.12.
Affected Version(s)
froxlor 0 < 2.3.12
froxlor 2.3.12
