Skip to main content
Vulnerability Database/CVE-2026-100714

CVE-2026-100714: Froxlor RCE Vulnerability

CVE-2026-100714 is a remote code execution flaw in Froxlor that allows administrators to execute arbitrary commands as root. This post explains its technical details, affected versions, impact, and mitigation steps.

Published:

CVE-2026-100714 Overview

CVE-2026-100714 is a command injection vulnerability in Froxlor server management panel versions prior to 2.3.12. The flaw resides in the system.letsencryptchallengepath setting, which is concatenated unescaped into an acme.sh command line executed by the root cron job. An administrator, or any actor able to write settings through the settings-import API, can inject additional acme.sh arguments such as --renew-hook, --pre-hook, or --post-hook to achieve arbitrary command execution as root. The vulnerability is tracked under CWE-88: Argument Injection.

Critical Impact

Successful exploitation yields arbitrary command execution as the root user on the Froxlor host at the next Let's Encrypt cron run.

Affected Products

  • Froxlor versions up to and including 2.3.10
  • Froxlor versions prior to 2.3.12
  • Any Froxlor deployment with the Let's Encrypt cron enabled

Discovery Timeline

  • 2026-09-26 - CVE-2026-100714 published to NVD
  • 2026-09-26 - Last updated in NVD database

Technical Details for CVE-2026-100714

Vulnerability Analysis

Froxlor stores the Let's Encrypt HTTP-01 challenge path in the system.letsencryptchallengepath setting. Unlike sibling settings hardened in GHSA-33mp, this field has no string_regexp validator and no required_otp guard. The raw value flows into lib/Froxlor/Cron/Http/LetsEncrypt/AcmeSh.php, where it is concatenated into an acme.sh command line and executed by the root cron through FileDir::safe_exec.

The safe_exec helper only blacklists classic shell metacharacters such as ;, |, &, >, <, \, $, ~, and ?. It does not strip spaces or quotes. As a result, the setting value is word-split by the shell into additional acme.sh arguments, giving the attacker control over flags passed to acme.sh.

Root Cause

The root cause is argument injection stemming from missing input validation on a privileged setting combined with an inadequate command sanitizer. The blacklist in safe_exec fails to account for whitespace-based argument splitting, violating the principle of safe command construction with explicit argument arrays.

Attack Vector

An attacker with administrator access, or any role able to write settings through the settings-import API, sets system.letsencryptchallengepath to a payload containing additional acme.sh flags. Supplying --renew-hook, --pre-hook, or --post-hook executes attacker-supplied shell commands as root at the next Let's Encrypt cron invocation. Alternatively, --config-home or --cert-home enables arbitrary file writes under root privileges. The vulnerability requires authenticated access but no user interaction, and exploitation is deterministic once the cron fires.

Detection Methods for CVE-2026-100714

Indicators of Compromise

  • Unexpected values in the system.letsencryptchallengepath setting containing whitespace, --, or acme.sh flag names such as renew-hook, pre-hook, post-hook, config-home, or cert-home.
  • Child processes spawned from the Froxlor cron process executing shell commands outside the normal acme.sh workflow.
  • New or modified files under paths referenced by --config-home or --cert-home arguments passed to acme.sh.

Detection Strategies

  • Audit the Froxlor panel_settings table for any settingvalue under system.letsencryptchallengepath that is not a simple filesystem path.
  • Monitor process execution telemetry for acme.sh invocations with suspicious hook flags or non-default --config-home/--cert-home arguments.
  • Review settings-import API usage and administrator audit logs for setting changes that correlate with later cron executions.

Monitoring Recommendations

  • Enable EDR process-ancestry logging on the Froxlor host and alert on root-owned shells launched by cron.
  • Baseline the normal acme.sh command line and alert on deviations in argument count or structure.
  • Forward Froxlor web and cron logs to a centralized log platform for retention and correlation.

How to Mitigate CVE-2026-100714

Immediate Actions Required

  • Upgrade Froxlor to version 2.3.12 or later without delay.
  • Inspect the current system.letsencryptchallengepath value and reset it to a known-good path if it contains spaces, quotes, or -- sequences.
  • Review administrator accounts and recent settings-import activity for unauthorized changes.

Patch Information

The vulnerability is fixed in Froxlor 2.3.12. Refer to the GitHub Security Advisory GHSA-3w4g-cmpj-rj42 and the VulnCheck Froxlor Command Injection Advisory for upstream remediation details.

Workarounds

  • Disable the Let's Encrypt cron job until the upgrade to 2.3.12 is applied.
  • Restrict administrator access and rotate credentials for any account with settings-write privileges.
  • Apply strict filesystem permissions to prevent unprivileged users from invoking the Froxlor cron pathway.
bash
# Verify the installed Froxlor version and the Let's Encrypt challenge path setting
php /var/www/froxlor/bin/froxlor-cli froxlor:version
mysql -e "SELECT settinggroup, varname, value FROM panel_settings \
  WHERE varname='letsencryptchallengepath';" froxlor

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.