PT-2026-99381 · Froxlor · Froxlor

·

CVE-2026-100710

·

Published

2026-09-26

·

Updated

2026-09-26

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Froxlor versions prior to 2.3.12
Description Certain API responses fail to filter sensitive columns, allowing an authenticated non-superadmin admin with the customers see all flag to access the panel domains.dkim privkey field. This occurs when the Domains::get(), Domains::listing(), SubDomains::get(), and the admin branch of SubDomains::listing() functions perform a wildcard SELECT over the panel domains table and return the row unmodified. An attacker can use these disclosed DKIM private signing keys to sign emails that pass DKIM verification and DMARC alignment for the affected domains.
Recommendations Update to version 2.3.12. As a temporary mitigation, restrict the use of the customers see all flag for non-superadmin accounts.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100710
GHSA-79GX-H528-J9XF

Affected Products

Froxlor