{"id":"CVE-2026-100716","published":"2026-09-26T14:16:57.583","lastModified":"2026-09-28T15:17:11.427","description":"Froxlor is a server administration panel. In versions 2.3.10 and earlier, the customer data-export (DataDump) cron fails to validate intermediate path components of the export destination: Froxlor\\FileDir::makeCorrectDir() contains an off-by-one in its path-component walk that skips the first segment below the customer home directory, and the guard in ExportCron.php checks only the final component with is_link(). An authenticated customer whose account has the export feature enabled can schedule an export into a genuine subdirectory of their own webspace, then replace an intermediate path component with a symlink before the root-owned cron runs. The cron's `chown -R` then recursively changes ownership of the linked directory tree — for example /etc — to the customer's UID, yielding host root and cross-tenant compromise. Exploitation is deterministic and requires no race. This is an incomplete fix of GHSA-75h4-... The issue is fixed in Froxlor 2.3.12.","cvssScore":9.9,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","cwes":["CWE-59"],"vendors":[],"products":[],"references":[{"url":"https://github.com/froxlor/froxlor/security/advisories/GHSA-2wjc-6mgx-hq42","tags":[]},{"url":"https://www.vulncheck.com/advisories/froxlor-before-2.3.12-privilege-escalation-via-symlink","tags":[]},{"url":"https://github.com/froxlor/froxlor/security/advisories/GHSA-2wjc-6mgx-hq42","tags":[]}],"exploitRefs":[{"url":"https://github.com/froxlor/froxlor/security/advisories/GHSA-2wjc-6mgx-hq42","tags":[]},{"url":"https://github.com/froxlor/froxlor/security/advisories/GHSA-2wjc-6mgx-hq42","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows an authenticated customer to exploit a symlink race condition to gain host root and cross-tenant access, due to improper path validation in the data export feature.","exploitability":"Exploitation is deterministic and requires no race condition, making it relatively easy for an attacker with the necessary permissions to execute.","blast_radius":"If exploited, the attacker can gain full control over the host system and potentially compromise other tenant accounts, leading to significant damage.","remediation":"Upgrade to Froxlor 2.3.12 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["auth-bypass","rce","web","path-traversal"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:48:51.907Z"}}