API Authentication Bypass in Froxlor Server Administration Software
CVE-2026-52793
8.1HIGH
What is CVE-2026-52793?
Froxlor, an open-source server administration tool, contains a significant API authentication bypass vulnerability prior to version 2.3.7. In its lib/Froxlor/Api/FroxlorRPC.php, the validateAuth method fails to enforce the necessary two-factor authentication checks (type_2fa or TOTP code) when validating API credentials. This oversight allows an attacker possessing valid API keys to access exposed API functions without the requisite second factor, potentially compromising customer data, domains, email, FTP accounts, databases, DNS records, and certificate material. The issue is addressed in version 2.3.7.
Affected Version(s)
froxlor <.3.7
