Data Exposure in Froxlor Open Source Server Administration Software
CVE-2026-62988

9CRITICAL

Key Information:

Vendor

Froxlor

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-62988?

Froxlor, an open-source server administration solution, has a vulnerability in its API that allows authenticated users to access sensitive data. Specifically, the API commands for retrieving customer and administrator details expose critical information such as password hashes and Base32-encoded TOTP seeds. This information could lead to unauthorized access to accounts, allowing attackers to bypass authentication protocols. Versions prior to 2.3.8 are affected by this issue, which has since been addressed in a security update.

Affected Version(s)

froxlor < 2.3.8

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.