Skip to main content
Vulnerability Database/CVE-2026-100709

CVE-2026-100709: Froxlor Auth Bypass Vulnerability

CVE-2026-100709 is an authentication bypass flaw in Froxlor that allows attackers to circumvent two-factor authentication due to improper token validation. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-100709 Overview

CVE-2026-100709 is an authentication bypass vulnerability in Froxlor through version 2.3.10. The flaw resides in how the server-management panel handles remembered two-factor authentication (2FA) tokens stored in the panel_2fa_tokens table. Froxlor stores only a numeric user ID in these tokens without recording whether the account belongs to the customer or administrator namespace. During login, the remembered-token lookup does not filter by account type. An attacker who controls a customer account whose numeric ID collides with an administrator ID, holds a valid remembered-2FA cookie, and already knows the administrator's password can bypass the TOTP second factor and obtain an authenticated administrator session. The issue is fixed in Froxlor 2.3.12.

Critical Impact

An attacker with a colliding customer ID, a valid remembered-2FA cookie, and knowledge of the target administrator password can bypass TOTP and gain administrator access to the Froxlor panel.

Affected Products

  • Froxlor versions up to and including 2.3.10
  • Froxlor 2.3.11 (prior to the 2.3.12 fix)
  • Froxlor server-management panel instances using remembered-2FA tokens

Discovery Timeline

  • 2026-09-26 - CVE-2026-100709 published to the National Vulnerability Database (NVD)
  • 2026-09-26 - Last updated in NVD database

Technical Details for CVE-2026-100709

Vulnerability Analysis

Froxlor manages two distinct account types: customers and administrators. Each type has its own ID namespace, meaning a customer and an administrator can legitimately share the same numeric ID. The panel_2fa_tokens table used to persist remembered-2FA cookies records only the numeric ID of the account that issued the token. It omits the account-type discriminator entirely.

When a user authenticates, Froxlor validates the password against the correct account table and then consults panel_2fa_tokens to determine whether the browser presenting the cookie should skip TOTP verification. The lookup matches on the token value and user ID but does not require the stored record to belong to the account type currently authenticating. A remembered-token row created for a customer therefore satisfies the check for an administrator with the same ID.

The weakness is classified under [CWE-287: Improper Authentication]. It does not weaken password authentication; the attacker must already possess the target administrator's password through a separate compromise, phishing, or credential reuse. The flaw strictly defeats the second factor.

Root Cause

The root cause is a missing namespace qualifier in both the token-storage schema and the lookup query. Because the schema stores only userid and the query joins only on userid and token value, Froxlor cannot distinguish a remembered-2FA token issued to customer ID 7 from one issued to administrator ID 7. The design implicitly trusts that user IDs are globally unique, but they are allocated from independent sequences per account type.

Attack Vector

Exploitation requires three preconditions. The attacker must control a Froxlor customer account whose numeric ID collides with a target administrator's ID. The attacker must hold a valid remembered-2FA cookie legitimately issued for that customer account. The attacker must already know the target administrator's password.

With these in place, the attacker submits the administrator's credentials to the login endpoint while presenting the customer-issued remembered-2FA cookie. Froxlor accepts the password, matches the cookie against a row in panel_2fa_tokens tied to the colliding ID, and establishes an authenticated administrator session without ever challenging for the TOTP code. See the GitHub Security Advisory GHSA-9fq7-9w8p-c3qh and the VulnCheck Advisory: Froxlor 2FA Bypass for upstream analysis.

Detection Methods for CVE-2026-100709

Indicators of Compromise

  • Administrator login events immediately followed by sensitive panel actions where no TOTP prompt was recorded in the application log.
  • Entries in panel_2fa_tokens whose associated numeric ID matches both a customer account and an administrator account.
  • Browser cookies presenting remembered-2FA values that successfully authenticate against administrator sessions after being issued to customer sessions.

Detection Strategies

  • Audit the panel_2fa_tokens table and cross-reference each userid against both the customer and administrator tables to identify ID collisions.
  • Review Froxlor and web-server access logs for administrator session establishment that lacks a preceding TOTP verification step.
  • Correlate source IP addresses of successful administrator logins with historical customer login activity for the same remembered-token value.

Monitoring Recommendations

  • Alert on any administrator authentication that completes without a corresponding TOTP challenge event in the application audit trail.
  • Monitor for repeated authentication attempts against the Froxlor admin login endpoint from IPs associated with low-privilege customer accounts.
  • Track creation of new customer accounts whose auto-assigned IDs overlap with existing administrator IDs.

How to Mitigate CVE-2026-100709

Immediate Actions Required

  • Upgrade all Froxlor instances to version 2.3.12 or later, which constrains remembered-token lookups by account type.
  • Invalidate all existing entries in panel_2fa_tokens to force reissuance of remembered-2FA cookies after the upgrade.
  • Rotate administrator passwords for any account whose numeric ID collides with an existing customer ID.
  • Review administrator session and audit logs for the period preceding the upgrade for evidence of unauthorized access.

Patch Information

The maintainers fixed the issue in Froxlor 2.3.12. Refer to the GitHub Security Advisory GHSA-9fq7-9w8p-c3qh for the patch commit and release notes. The fix scopes the remembered-token lookup to the authenticating account type so a customer-issued token can no longer match an administrator record.

Workarounds

  • Disable the remembered-2FA feature for administrator accounts until the panel is upgraded to 2.3.12.
  • Manually truncate the panel_2fa_tokens table to invalidate any outstanding tokens that could be abused through ID collision.
  • Restrict administrator panel access by source IP using web-server or firewall rules to limit exposure of the login endpoint.
bash
# Configuration example: invalidate remembered-2FA tokens pending patch
mysql -u froxlor -p froxlor -e "TRUNCATE TABLE panel_2fa_tokens;"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.