Froxlor · Froxlor · CVE-2026-100709
**Name of the Vulnerable Software and Affected Versions**
Froxlor versions prior to 2.3.12
**Description**
The software stores only a numeric user ID in remembered-2FA tokens within `panel 2fa tokens` without recording the account namespace. During login, the remembered-token lookup is not constrained to the customer or administrator account type. Since customer and administrator IDs are allocated from separate namespaces, a token issued to a customer with a specific ID can match an administrator with the same ID. An attacker who controls a customer account with a colliding ID, possesses a valid remembered-2FA cookie, and knows the target administrator's password can bypass the Time-based One-Time Password (TOTP) second factor to obtain an authenticated administrator session. This issue is a second-factor bypass and does not defeat password authentication.
**Recommendations**
Update to version 2.3.12.