Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Robinmoschini

#36873of 57,305
7.7Total CVSS
Vulnerabilities · 1
PT-2026-99380
7.7
2026-09-26
Froxlor · Froxlor · CVE-2026-100709
**Name of the Vulnerable Software and Affected Versions** Froxlor versions prior to 2.3.12 **Description** The software stores only a numeric user ID in remembered-2FA tokens within `panel 2fa tokens` without recording the account namespace. During login, the remembered-token lookup is not constrained to the customer or administrator account type. Since customer and administrator IDs are allocated from separate namespaces, a token issued to a customer with a specific ID can match an administrator with the same ID. An attacker who controls a customer account with a colliding ID, possesses a valid remembered-2FA cookie, and knows the target administrator's password can bypass the Time-based One-Time Password (TOTP) second factor to obtain an authenticated administrator session. This issue is a second-factor bypass and does not defeat password authentication. **Recommendations** Update to version 2.3.12.