Data Exposure in Froxlor Open Source Server Administration Software
CVE-2026-62988
9CRITICAL
What is CVE-2026-62988?
Froxlor, an open-source server administration solution, has a vulnerability in its API that allows authenticated users to access sensitive data. Specifically, the API commands for retrieving customer and administrator details expose critical information such as password hashes and Base32-encoded TOTP seeds. This information could lead to unauthorized access to accounts, allowing attackers to bypass authentication protocols. Versions prior to 2.3.8 are affected by this issue, which has since been addressed in a security update.
Affected Version(s)
froxlor < 2.3.8
