← Back to search

CVE-2026-100715

9.6 CRITICALpublic exploit available

Published 2026-09-26 · Updated 2026-09-28

AI risk analysis

Summary
The flaw allows an authenticated customer to plant a symlink in the FTP home directory, leading to arbitrary file deletion via the cron task. This can result in cross-tenant data destruction and host denial of service.
Exploitability
Exploitation is moderately hard as it requires an authenticated user with write access to the FTP home directory and timing to plant the symlink between task insertion and cron execution.
Blast radius
The impact is high, as it can lead to cross-tenant data destruction and host denial of service.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to Froxlor 2.3.12 or later.
rceauth-bypasscronfile-deletionsymlink

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via symlink following in the FTP data deletion cron task. Cron task 8 (deleteFtpData), queued when an FTP account is deleted, calls FileDir::makeCorrectDir() without the $fixed_homedir argument, so the symlink component walk is skipped, and then executes 'rm -rf' as root on the resulting path with string-level guards only. Because makeCorrectDir() appends a trailing slash, GNU rm dereferences a symlink used either as an intermediate path component or as the final component. An authenticated customer who can write to the FTP home directory can plant a symlink between task insertion and cron execution, causing the root cron job to recursively delete arbitrary directory trees, resulting in cross-tenant data destruction and host denial of service. This issue is fixed in Froxlor 2.3.12.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H

Weaknesses

CWE-59

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.