PT-2026-99387 · Froxlor · Froxlor

·

CVE-2026-100716

·

Published

2026-09-26

·

Updated

2026-09-28

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Froxlor versions prior to 2.3.12
Description An authenticated customer with the export feature enabled can achieve host root and cross-tenant compromise. The issue occurs because the customer data-export (DataDump) cron fails to validate intermediate path components of the export destination. Specifically, the makeCorrectDir() function in FroxlorFileDir contains an off-by-one error during its path-component walk, skipping the first segment below the customer home directory. Additionally, the guard in ExportCron.php only checks the final component using is link(). An attacker can schedule an export to a subdirectory and replace an intermediate path component with a symlink before the root-owned cron executes. This causes the chown -R command to recursively change the ownership of the linked directory tree, such as /etc, to the customer's UID.
Recommendations Update to version 2.3.12.

Exploit

Fix

LPE

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100716
GHSA-2WJC-6MGX-HQ42

Affected Products

Froxlor