CVE-2026-100714
9.1 CRITICALpublic exploit availablePublished 2026-09-26 · Updated 2026-09-26
AI risk analysis
- Summary
- The flaw allows an attacker to inject acme.sh options, leading to arbitrary command execution as root during Let's Encrypt certificate renewals.
- Exploitability
- Exploitation is relatively easy if an attacker can write settings, such as through the settings-import API.
- Blast radius
- If exploited, attackers could gain full control over the system, leading to severe data breaches or system compromise.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to Froxlor version 2.3.12 or later.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
Froxlor before 2.3.12 does not restrict or escape the system.letsencryptchallengepath setting: unlike sibling settings hardened in GHSA-33mp, the field has no string_regexp or required_otp guard, and its value is concatenated unescaped into the acme.sh command line built in lib/Froxlor/Cron/Http/LetsEncrypt/AcmeSh.php and executed by the root cron via FileDir::safe_exec. Because safe_exec only blacklists shell metacharacters such as ; | & > < \ $ ~ ?, spaces and quotes survive and the value is word-split into additional acme.sh arguments. An administrator, or any actor able to write settings (for example through the settings-import API), can therefore inject acme.sh options such as --renew-hook, --pre-hook or --post-hook to obtain arbitrary command execution as root at the next Let's Encrypt cron run, or use --config-home/--cert-home for arbitrary file writes. Versions up to and including 2.3.10 are affected; the issue is fixed in 2.3.12.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Weaknesses
CWE-88
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-42322PoC
- CRITICALCVE-2026-75799
- CRITICALCVE-2026-84502
- HIGHCVE-2026-89036PoC
- CRITICALCVE-2023-54399
- CRITICALCVE-2023-54400PoC
- HIGHCVE-2025-1281
- CRITICALCVE-2025-29296
Related by shared AI tags and CWE weakness class. Browse the full archive.