CVE-2026-100711 Overview
CVE-2026-100711 is a session management vulnerability in Froxlor server administration panel versions before 2.3.12. The application fails to invalidate active sessions, API keys, and two-factor authentication (2FA) trust cookies when a user changes their password. Attackers who previously obtained a session cookie, API key, or 2FA trust token retain full account access after the password rotation. This behavior defeats a core incident response action commonly used to evict intruders. The weakness is tracked under CWE-613: Insufficient Session Expiration.
Critical Impact
Password rotation does not revoke existing authentication material, allowing attackers with stolen sessions, API keys, or 2FA trust cookies to maintain persistent access to Froxlor accounts.
Affected Products
- Froxlor versions prior to 2.3.12
- Froxlor panel web sessions
- Froxlor API keys and 2FA trust cookies
Discovery Timeline
- 2026-09-26 - CVE-2026-100711 published to NVD
- 2026-09-28 - Last updated in NVD database
Technical Details for CVE-2026-100711
Vulnerability Analysis
Froxlor is an open source server administration panel used to manage hosting environments, domains, and customer accounts. The vulnerability resides in the account credential update workflow. When a user changes their password through the panel, Froxlor updates the stored credential hash but does not iterate over and invalidate other authentication artifacts tied to the account.
Three artifact classes remain valid after a password change: panel session identifiers stored server-side, API keys issued for programmatic access, and persistent 2FA trust cookies that mark a browser as previously verified. Any of these artifacts obtained by an attacker before the password change continues to authenticate requests until it reaches its own natural expiration.
The practical result is that standard incident response guidance — "rotate the password" — fails to evict an active intruder. Administrators who detect compromise and change the password will believe the account is secured while the attacker continues to issue authenticated requests.
Root Cause
The root cause is insufficient session expiration ([CWE-613]). The credential change handler lacks logic to purge the session store, revoke API tokens, and clear 2FA trust records associated with the user identifier. Each authentication mechanism treats its lifecycle independently rather than binding validity to the current password state.
Attack Vector
Exploitation is network-based and requires no user interaction. An attacker must first obtain one of the long-lived authentication artifacts through a separate initial access vector such as session hijacking, API key theft from a developer workstation, cross-site scripting, or compromise of a browser previously enrolled for 2FA trust. Once held, the artifact survives password rotation performed by the legitimate account owner or an administrator responding to an incident. The vulnerability is a persistence enabler rather than an initial access vector.
No verified proof-of-concept code is published. The behavior is described in the GitHub Security Advisory GHSA-57wv-g7m3-hmff and the VulnCheck advisory.
Detection Methods for CVE-2026-100711
Indicators of Compromise
- Authenticated Froxlor requests originating from a session cookie issued before a recent password change event.
- API calls using a key whose creation timestamp predates a user credential rotation.
- 2FA bypass events where a trust cookie satisfies the second factor from an unexpected network location.
- Account activity from two distinct IP addresses or user agents following a password reset.
Detection Strategies
- Correlate Froxlor authentication logs with password change events; flag any session or API activity whose issuance predates the latest credential update.
- Baseline API key usage per account and alert on continued use of keys after an administrative password reset.
- Monitor web access logs for session identifiers that persist across a credential change boundary.
Monitoring Recommendations
- Forward Froxlor application and web server logs to a centralized log platform for retention and correlation.
- Alert on any authenticated panel action within 24 hours of a password change where the session or token identifier is older than the change timestamp.
- Track geographic and user-agent diversity on administrative accounts to surface concurrent sessions.
How to Mitigate CVE-2026-100711
Immediate Actions Required
- Upgrade Froxlor to version 2.3.12 or later on all panel instances.
- After upgrading, force a global logout and rotate all API keys and 2FA trust cookies for accounts suspected of prior compromise.
- Audit API key inventories and revoke keys that are no longer required.
- Review authentication logs for session identifiers that remained active across prior password changes.
Patch Information
Froxlor 2.3.12 addresses the vulnerability by invalidating active sessions, API keys, and 2FA trust cookies when a user password is changed. Refer to the Froxlor GitHub Security Advisory for release details and the fix commit.
Workarounds
- Manually revoke all active sessions through direct session store clearing after any password change on unpatched instances.
- Rotate all API keys for an account whenever its password is changed.
- Clear 2FA trust cookies by disabling and re-enabling 2FA for the affected account.
- Restrict panel access by IP allowlist to reduce the exposure window for stolen artifacts.
# Verify installed Froxlor version meets the fixed release
php -r 'require "/var/www/froxlor/lib/functions.php"; echo FROXLOR_VERSION . PHP_EOL;'
# After upgrade, truncate the active sessions table to force re-authentication
mysql -u root -p froxlor -e "TRUNCATE TABLE panel_sessions;"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.