API Authentication Bypass in Froxlor Server Administration Software
CVE-2026-52793

8.1HIGH

Key Information:

Vendor

Froxlor

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-52793?

Froxlor, an open-source server administration tool, contains a significant API authentication bypass vulnerability prior to version 2.3.7. In its lib/Froxlor/Api/FroxlorRPC.php, the validateAuth method fails to enforce the necessary two-factor authentication checks (type_2fa or TOTP code) when validating API credentials. This oversight allows an attacker possessing valid API keys to access exposed API functions without the requisite second factor, potentially compromising customer data, domains, email, FTP accounts, databases, DNS records, and certificate material. The issue is addressed in version 2.3.7.

Affected Version(s)

froxlor <.3.7

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.