OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-100709

HIGH · CVSS 7.5 EPSS 0.29% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-26 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

Froxlor versions up to 2.3.10 are vulnerable due to improper handling of remembered-2FA tokens, which only store numeric user IDs without differentiating between customer and administrator namespaces. This flaw allows an attacker with a customer account that shares an ID with an administrator to bypass the second-factor authentication if they possess a valid remembered-2FA cookie and know the administrator's password. Organizations using affected versions should prioritize upgrading to 2.3.12 to mitigate the risk of unauthorized administrative access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100709
Severity
HIGH
CVSS
7.5
EPSS
0.29%

Original NVD Description

Froxlor through 2.3.10 stores only a numeric user ID in remembered-2FA tokens (panel_2fa_tokens) without recording the account namespace, and the remembered-token lookup during login is not constrained to the customer or administrator account type. Because customer and administrator IDs are allocated from separate namespaces, a remembered-2FA token legitimately issued to a customer with a given ID also matches an administrator with the same ID. An attacker who controls a customer account with a colliding ID, holds a valid remembered-2FA cookie for it, and already knows the target administrator's password can bypass the administrator's TOTP second factor and obtain an authenticated administrator session. This is a second-factor bypass only; it does not defeat password authentication. Fixed in 2.3.12.