Symlink-Following Flaw in Froxlor's Key Handling
CVE-2026-41236
8.8HIGH
What is CVE-2026-41236?
Froxlor, an open-source server administration panel, is affected by a security flaw in version 2.3.6, which allows for unchecked symlink-follows during SSH key synchronization. This vulnerability enables an attacker with access to a customer account to manipulate the SSH keys via symbolic links. By replacing the ~/.ssh/authorized_keys file with a symlink to the root's authorized keys file, an attacker can gain unauthorized root access through the automated provisioning code used in Froxlor's cron tasks. It is crucial for users to upgrade to version 2.3.7, which contains a patch to address this issue effectively.
Affected Version(s)
froxlor = 2.3.6
