OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-100717

CRITICAL · CVSS 9.9 EPSS 0.30% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-26 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

Versions 2.3.10 and earlier of the Froxlor server administration panel are vulnerable to a critical injection flaw that allows authenticated low-privilege users to exploit the userinfo component of URLs. By crafting a subdomain redirect URL with a carriage return/line feed payload, attackers can inject arbitrary configuration directives into the web server's configuration files, potentially leading to server-wide impacts such as response hijacking or unauthorized file access. Organizations using affected versions of Froxlor should prioritize upgrading to version 2.3.12 to mitigate this severe risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100717
Severity
CRITICAL
CVSS
9.9
EPSS
0.30%
Apache Nginx

Original NVD Description

froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl rejects carriage return and line feed characters only in the path, query and fragment components returned by parse_url, and never inspects the userinfo (user:pass@) components. This is an incomplete fix for GHSA-c3p2. An authenticated low-privilege customer with subdomain-create rights (no admin or change_serversettings privilege required) can supply a subdomain redirect URL that carries a CR/LF payload in the userinfo portion (e.g. http://user%0areturn 200 "pwned";%0a@evil.com/). The value passes validation, survives IDNA encoding, and is written verbatim into the generated nginx or Apache vhost configuration, allowing the attacker to break out of the emitted directive and inject arbitrary web-server configuration lines. froxlor regenerates and reloads the web-server configuration as root, so the injected directives take effect server-wide and can hijack responses or read local files. The issue is fixed in version 2.3.12.