CVE-2026-100715 Overview
CVE-2026-100715 is an arbitrary file deletion vulnerability in Froxlor through version 2.3.10. The flaw resides in cron task 8 (deleteFtpData), which executes rm -rf as root against an attacker-influenced path. An authenticated customer with write access to an FTP home directory can plant a symbolic link between task insertion and cron execution. GNU rm then dereferences the symlink, recursively deleting arbitrary directory trees outside the tenant boundary. The issue is tracked under CWE-59: Improper Link Resolution Before File Access and is fixed in Froxlor 2.3.12.
Critical Impact
A low-privilege authenticated tenant can trigger root-level recursive deletion of arbitrary directories, causing cross-tenant data destruction and host denial of service.
Affected Products
- Froxlor versions up to and including 2.3.10
- Froxlor 2.3.11 (fixed in 2.3.12)
- Shared-hosting deployments where multiple tenants hold FTP accounts
Discovery Timeline
- 2026-09-26 - CVE-2026-100715 published to NVD
- 2026-09-28 - Last updated in NVD database
- Froxlor 2.3.12 - Vendor releases patched version
Technical Details for CVE-2026-100715
Vulnerability Analysis
Froxlor queues cron task 8 (deleteFtpData) when a customer deletes an FTP account. The task resolves the target path via FileDir::makeCorrectDir() and then invokes rm -rf under the root account. The resulting operation inherits root privilege and operates on a path that an unprivileged user controls on disk.
The cron handler enforces only string-level guards on the path. It does not canonicalize the final target or verify that intermediate components are real directories owned by the tenant. This gap enables a classic time-of-check to time-of-use condition against the filesystem.
Root Cause
The FileDir::makeCorrectDir() function is invoked without the $fixed_homedir argument. That argument controls the symlink component walk that normally rejects or resolves link components in the path. Skipping the walk leaves symlinks intact in the string passed to rm.
makeCorrectDir() also appends a trailing slash to the path. GNU rm treats a path with a trailing slash as a directory reference and dereferences symlinks encountered as intermediate components or as the final component. The combination lets a tenant redirect the deletion to any directory the root user can access.
Attack Vector
An authenticated customer first requests deletion of an FTP account tied to a directory they control. Before the cron task fires, the attacker replaces a path component inside the FTP home with a symlink pointing to an arbitrary directory such as /var/www, /home, or /etc. When cron task 8 executes, root-owned rm -rf follows the symlink and recursively removes the target tree. The result is cross-tenant data loss or host-level denial of service.
No verified exploitation code is published. See the GitHub Security Advisory GHSA-px4q-2rf7-cvcf and the VulnCheck advisory for additional detail.
Detection Methods for CVE-2026-100715
Indicators of Compromise
- Unexpected deletion of directories outside tenant FTP home paths following execution of Froxlor cron jobs.
- Entries in the Froxlor task queue referencing deleteFtpData (task type 8) immediately preceding unexplained filesystem loss.
- Symbolic links present inside FTP home directories that resolve to paths outside the tenant chroot.
Detection Strategies
- Audit the Froxlor panel_tasks table for queued deleteFtpData entries and correlate the referenced path with subsequent rm -rf invocations in system logs.
- Enable Linux auditd rules on unlink, unlinkat, and rmdir syscalls executed by the root user originating from the Froxlor cron process.
- Scan tenant FTP home directories for symbolic links whose targets escape the tenant base directory.
Monitoring Recommendations
- Alert on root-owned rm -rf executions where the target path contains a user-writable component.
- Monitor Froxlor cron execution logs for task 8 completion events and verify that deleted paths match the originally queued FTP account directory.
- Track filesystem integrity on sensitive paths (/etc, /var/www, tenant home roots) using a host integrity monitor.
How to Mitigate CVE-2026-100715
Immediate Actions Required
- Upgrade Froxlor to version 2.3.12 or later on all panel installations.
- Review the panel_tasks queue and cancel any pending deleteFtpData entries from untrusted customers before upgrading.
- Audit tenant FTP home directories for pre-planted symbolic links that target paths outside the tenant scope.
Patch Information
The vulnerability is fixed in Froxlor 2.3.12. The patch supplies the $fixed_homedir argument to FileDir::makeCorrectDir() so the symlink component walk executes before the path is handed to rm. Refer to the GitHub Security Advisory GHSA-px4q-2rf7-cvcf for the official fix commit and release notes.
Workarounds
- Temporarily disable cron task 8 (deleteFtpData) and perform FTP account cleanup manually under administrator supervision.
- Restrict the cron runner so that FTP data deletion executes under a non-root service account scoped to tenant directories.
- Mount tenant FTP home directories with the nosymfollow option where supported by the kernel and filesystem.
# Verify installed Froxlor version and upgrade
php /var/www/froxlor/bin/froxlor-cli --version
# Example: block symlink traversal on tenant mounts (kernel >= 5.10)
mount -o remount,nosymfollow /var/customers
# Audit queued deleteFtpData jobs before upgrade
mysql -e "SELECT id, type, data FROM panel_tasks WHERE type = 8;" froxlor
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.