OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-100716

CRITICAL · CVSS 9.9 EPSS 0.39% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-26 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

Froxlor versions 2.3.10 and earlier are vulnerable due to a flaw in the customer data-export feature, allowing authenticated users to exploit symlink manipulation to gain root access on the host system. This critical vulnerability can lead to cross-tenant compromise and unauthorized ownership changes of sensitive directories, making it imperative for all users of Froxlor to upgrade to version 2.3.12 immediately to mitigate the risk. Organizations utilizing Froxlor for server administration should prioritize this update to safeguard their environments.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100716
Severity
CRITICAL
CVSS
9.9
EPSS
0.39%

Original NVD Description

Froxlor is a server administration panel. In versions 2.3.10 and earlier, the customer data-export (DataDump) cron fails to validate intermediate path components of the export destination: Froxlor\FileDir::makeCorrectDir() contains an off-by-one in its path-component walk that skips the first segment below the customer home directory, and the guard in ExportCron.php checks only the final component with is_link(). An authenticated customer whose account has the export feature enabled can schedule an export into a genuine subdirectory of their own webspace, then replace an intermediate path component with a symlink before the root-owned cron runs. The cron's `chown -R` then recursively changes ownership of the linked directory tree — for example /etc — to the customer's UID, yielding host root and cross-tenant compromise. Exploitation is deterministic and requires no race. This is an incomplete fix of GHSA-75h4-... The issue is fixed in Froxlor 2.3.12.