DNS Manipulation Vulnerability in Froxlor Open Source Server Administration Software
CVE-2026-54543

5.4MEDIUM

Key Information:

Vendor

Froxlor

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-54543?

Froxlor, an open-source server administration tool, contains a vulnerability in its DomainZones.add API command prior to version 2.3.8. This issue arises due to insufficient validation of user-controlled record and type values, allowing authenticated customers with DNS-zone permissions to inject crafted values. The inadequately handled inputs can lead to the creation of unauthorized resource-record lines in the BIND zone file. As a result, this can manipulate DNS data and potentially affect availability within a managed zone, posing significant risks to users and services relying on Froxlor for server management.

Affected Version(s)

froxlor < 2.3.8

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.