← Back to search

CVE-2026-100716

9.9 CRITICALpublic exploit available

Published 2026-09-26 · Updated 2026-09-28

AI risk analysis

Summary
The flaw allows an authenticated customer to exploit a symlink race condition to gain host root and cross-tenant access, due to improper path validation in the data export feature.
Exploitability
Exploitation is deterministic and requires no race condition, making it relatively easy for an attacker with the necessary permissions to execute.
Blast radius
If exploited, the attacker can gain full control over the host system and potentially compromise other tenant accounts, leading to significant damage.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to Froxlor 2.3.12 or later.
auth-bypassrcewebpath-traversal

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Froxlor is a server administration panel. In versions 2.3.10 and earlier, the customer data-export (DataDump) cron fails to validate intermediate path components of the export destination: Froxlor\FileDir::makeCorrectDir() contains an off-by-one in its path-component walk that skips the first segment below the customer home directory, and the guard in ExportCron.php checks only the final component with is_link(). An authenticated customer whose account has the export feature enabled can schedule an export into a genuine subdirectory of their own webspace, then replace an intermediate path component with a symlink before the root-owned cron runs. The cron's `chown -R` then recursively changes ownership of the linked directory tree — for example /etc — to the customer's UID, yielding host root and cross-tenant compromise. Exploitation is deterministic and requires no race. This is an incomplete fix of GHSA-75h4-... The issue is fixed in Froxlor 2.3.12.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-59

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.