CSRF Bypass Vulnerability in Froxlor Open Source Server Administration Software
CVE-2026-55593
6.5MEDIUM
What is CVE-2026-55593?
Froxlor, an open-source server administration software, suffers from a vulnerability where the entry point lib/ajax.php bypasses centralized request validation before allowing state-changing requests. This flaw specifically impacts the editapikey action, which updates settings without validating a CSRF token. As a result, an unauthenticated attacker could manipulate an authenticated administrator's session, potentially adding their own IP address to an API key's allowed_from list or removing its expiration date, thereby compromising the key's intended security restrictions. This vulnerability was addressed in version 2.3.8.
Affected Version(s)
froxlor < 2.3.8
