PT-2026-99385 · Froxlor · Froxlor

·

CVE-2026-100714

·

Published

2026-09-26

·

Updated

2026-09-26

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Froxlor versions prior to 2.3.12
Description Insufficient restriction and escaping of the system.letsencryptchallengepath setting allows for command injection. The value of this setting is concatenated unescaped into the acme.sh command line within the lib/Froxlor/Cron/Http/LetsEncrypt/AcmeSh.php file and executed by the root cron using the FileDir::safe exec() function. Since safe exec() only blacklists specific shell metacharacters, spaces and quotes remain, allowing the value to be split into additional acme.sh arguments. An administrator or an actor with permissions to modify settings, such as through the settings-import API, can inject options like --renew-hook, --pre-hook, or --post-hook to achieve arbitrary command execution as root during the next Let's Encrypt cron run, or use --config-home and --cert-home for arbitrary file writes.
Recommendations Update to version 2.3.12 or later.

Exploit

Fix

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100714
GHSA-3W4G-CMPJ-RJ42

Affected Products

Froxlor