PT-2026-99384 · Froxlor · Froxlor

·

CVE-2026-100713

·

Published

2026-09-26

·

Updated

2026-09-26

CVSS v3.1

7.8

High

VectorAV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Froxlor versions prior to 2.3.12
Description A time-of-check time-of-use (TOCTOU) race condition exists in the SSH key synchronization cron within the SshKeys::generateFiles() function located in lib/Froxlor/Cron/System/SshKeys.php. TOCTOU is a software bug where a program checks the state of a resource before using it, but the state changes between the check and the use. The validation performed by FileDir::makeCorrectDir() and makeCorrectFile() occurs only at check time, while the filesystem path is re-resolved as root during the write process. On installations where the system.allow customer shell variable is set to 1, granting customers local shell access, an attacker can replace their ~/.ssh directory with a symlink after the check but before the write. This allows the root-run cron to append the customer's public key to /root/.ssh/authorized keys and change the ownership of /root/.ssh to the customer, leading to full root compromise of the panel host.
Recommendations Update to version 2.3.12. As a temporary mitigation, set the system.allow customer shell variable to 0 to restrict local shell access for customers.

Exploit

Fix

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100713
GHSA-927X-9JFH-MQ42

Affected Products

Froxlor