OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-100708

HIGH · CVSS 7.1 EPSS 0.13% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-26 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

Froxlor versions prior to 2.3.13 expose sensitive TLS private key information through the Certificates.get and Certificates.listing API commands, allowing low-privileged authenticated users to access their own domain's private keys and enabling resellers or admin accounts to retrieve keys from other users. This vulnerability can lead to severe security risks, including domain impersonation, passive decryption of TLS traffic, and active man-in-the-middle attacks. Organizations using Froxlor should prioritize patching to mitigate these risks, especially those with multi-tenant environments or offering reseller services.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100708
Severity
HIGH
CVSS
7.1
EPSS
0.13%

Original NVD Description

Froxlor before 2.3.13 returns the ssl_key_file column — which stores the raw PEM TLS private-key content — verbatim in the JSON responses of the Certificates.get and Certificates.listing API commands, because the results of the underlying domain_ssl_settings queries are passed through ApiCommand::response() without any field stripping or allowlist. A low-privileged authenticated customer API caller can retrieve the private keys of their own domains' certificates, including Let's Encrypt keys that Froxlor generates server-side and stores root-only (0600) and to which the customer otherwise has no filesystem access; reseller and customers_see_all admin accounts can dump the private keys of other principals through the same sink. Disclosed keys enable domain impersonation, passive decryption of captured TLS traffic, and active machine-in-the-middle attacks.