PT-2026-99379 · Froxlor · Froxlor

·

CVE-2026-100708

·

Published

2026-09-26

·

Updated

2026-09-26

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Froxlor versions prior to 2.3.13
Description An issue exists where the raw PEM TLS private-key content stored in the ssl key file column is returned verbatim in JSON responses. This occurs because results from domain ssl settings queries are processed by the ApiCommand::response() function without field stripping or an allowlist. This allows low-privileged authenticated API users to retrieve private keys for their own domains, including server-side generated Let's Encrypt keys that are normally restricted to root filesystem access. Additionally, reseller and customers see all admin accounts can extract private keys belonging to other principals via the 'Certificates.get' and 'Certificates.listing' API endpoints. Exposure of these keys can lead to domain impersonation, passive decryption of TLS traffic, and active machine-in-the-middle attacks.
Recommendations Update Froxlor to version 2.3.13 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100708
GHSA-6Q2V-JJQ5-M2C8

Affected Products

Froxlor