CVE-2026-100713
7.8 HIGHpublic exploit availablePublished 2026-09-26 · Updated 2026-09-26
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
Froxlor 2.3.10 and earlier contain a time-of-check time-of-use (TOCTOU) race condition in the SSH key synchronization cron (lib/Froxlor/Cron/System/SshKeys.php, SshKeys::generateFiles). The containment/symlink validation performed by FileDir::makeCorrectDir()/makeCorrectFile() is done only at check time; the live filesystem path is re-resolved as root at write time (file_put_contents with FILE_APPEND|LOCK_EX, followed by chmod/chown/chgrp), with a database round-trip and file reads in between, and no path or file-descriptor pinning (no O_NOFOLLOW or openat2(RESOLVE_NO_SYMLINKS)). On installations where the non-default setting system.allow_customer_shell=1 grants customers local shell access, a customer can atomically swap their ~/.ssh directory for a symlink after the check and before the write, causing the root-run cron to append the customer's public key to /root/.ssh/authorized_keys and to chown /root/.ssh to the customer, resulting in full root compromise of the panel host. The cron re-runs on every interval, allowing unlimited attempts. This is a residual race that bypasses the check-time fix introduced for GHSA-mq5v-... . The issue is fixed in Froxlor 2.3.12.
CVSS vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Weaknesses
CWE-367
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-100597PoC
- MEDIUMCVE-2026-101088PoC
- MEDIUMCVE-2026-47621PoC
- MEDIUMCVE-2026-54020PoC
- UNSCOREDCVE-2026-54575PoC
- UNSCOREDCVE-2026-54576PoC
- UNSCOREDCVE-2026-54587PoC
- HIGHCVE-2026-55567PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.