CVE-2026-100716 Overview
CVE-2026-100716 is a symlink-based privilege escalation vulnerability in Froxlor, an open-source server administration panel. Versions 2.3.10 and earlier contain a flawed path validation routine in the customer data-export (DataDump) cron job. An authenticated customer with the export feature enabled can replace an intermediate directory in the export path with a symbolic link before the root-owned cron executes. The subsequent chown -R call then transfers ownership of the linked directory tree, such as /etc, to the attacker's UID. This produces host root compromise and cross-tenant impact. The issue is tracked under [CWE-59] Link Following and fixed in Froxlor 2.3.12.
Critical Impact
Authenticated customers can escalate to host root and compromise other tenants on shared Froxlor hosts through deterministic symlink abuse of the DataDump cron.
Affected Products
- Froxlor server administration panel versions 2.3.10 and earlier
- Froxlor deployments with the customer data-export (DataDump) feature enabled
- Shared hosting environments running vulnerable Froxlor instances
Discovery Timeline
- 2026-09-26 - CVE-2026-100716 published to NVD
- 2026-09-28 - Last updated in NVD database
Technical Details for CVE-2026-100716
Vulnerability Analysis
The vulnerability resides in the Froxlor DataDump cron workflow that packages and relocates customer export archives. The export destination path is validated by Froxlor\FileDir::makeCorrectDir(), which walks path components to confirm each segment is safe. An off-by-one error causes the first segment beneath the customer home directory to be skipped during the check. The guard in ExportCron.php compounds the issue by inspecting only the final path component with is_link(). Intermediate directories therefore receive no symlink validation. When the root-owned cron later issues a recursive chown, it follows any symbolic link planted in those unchecked segments.
Root Cause
The root cause combines two defects: an off-by-one iteration in makeCorrectDir() and an incomplete symlink check in ExportCron.php. The vendor patch for a prior advisory (GHSA-75h4-...) addressed the final component but left intermediate components unverified. This classifies as link following [CWE-59], a TOCTOU-adjacent condition that in this case does not require winning a race because the attacker controls the directory structure between scheduling and execution.
Attack Vector
An authenticated Froxlor customer whose account has the export feature enabled schedules a data export into a legitimate subdirectory of their own webspace. Before the root-owned cron runs, the attacker replaces an intermediate directory in that path with a symbolic link pointing to a sensitive host directory such as /etc, /root, or another customer's document root. When the cron executes chown -R with the customer's UID, ownership of the entire linked tree transfers to the attacker. The attacker then edits files such as /etc/passwd, /etc/shadow, or /etc/sudoers to obtain root. Exploitation is deterministic and requires no timing race.
No verified proof-of-concept code is published. Refer to the GitHub Security Advisory GHSA-2wjc-6mgx-hq42 and the VulnCheck Advisory for technical specifics.
Detection Methods for CVE-2026-100716
Indicators of Compromise
- Symbolic links present inside customer webspace export directories that resolve outside the customer home tree.
- Unexpected ownership changes on system directories such as /etc, /root, or /var matching a customer UID.
- Froxlor cron log entries referencing DataDump exports immediately preceding filesystem anomalies.
- New or modified entries in /etc/passwd, /etc/shadow, or /etc/sudoers not attributable to administrator action.
Detection Strategies
- Audit filesystem ownership on sensitive directories and compare against a known-good baseline after each DataDump cron cycle.
- Hunt for symlinks inside customer webroots whose targets escape the customer home directory using find / -xdev -type l -lname '/*'.
- Correlate Froxlor application logs showing export scheduling events with system-level chown activity captured by audit daemons.
Monitoring Recommendations
- Enable Linux auditd rules on chown, lchown, and symlinkat syscalls to capture ownership changes and symlink creation across tenant directories.
- Forward Froxlor cron logs and audit telemetry to a centralized data lake for correlation and retention.
- Alert on any ownership change to files under /etc, /root, /var/lib, or paths outside /var/customers/ performed by cron-invoked processes.
How to Mitigate CVE-2026-100716
Immediate Actions Required
- Upgrade Froxlor to version 2.3.12 or later on every affected host without delay.
- Disable the customer data-export (DataDump) feature until the upgrade is complete.
- Review customer webspace directories for existing symlinks pointing outside the customer home and remove any that are unauthorized.
- Audit /etc, /root, and other sensitive paths for unexpected ownership and restore correct permissions.
Patch Information
Froxlor 2.3.12 resolves CVE-2026-100716 by correcting the off-by-one in Froxlor\FileDir::makeCorrectDir() and extending symlink validation across all intermediate path components in ExportCron.php. Administrators should apply the official release from the GitHub Security Advisory GHSA-2wjc-6mgx-hq42. Note that this release supersedes an incomplete fix delivered in a prior advisory (GHSA-75h4-...).
Workarounds
- Disable the DataDump cron job and the customer export feature until the patch is applied.
- Restrict customer accounts that have the export feature enabled to a minimal, trusted set.
- Run the DataDump cron under a non-root service account with constrained write capabilities where operationally feasible.
# Configuration example: disable DataDump cron until Froxlor 2.3.12 is deployed
# Comment out the Froxlor cron entry
sudo sed -i 's|^\(.*froxlor/scripts/froxlor_master_cronjob.php.*\)|# \1|' /etc/cron.d/froxlor
# Hunt for suspicious symlinks inside customer webspace
sudo find /var/customers -xdev -type l \
-exec sh -c 'target=$(readlink -f "$1"); case "$target" in /var/customers/*) ;; *) echo "SUSPICIOUS: $1 -> $target";; esac' _ {} \;
# Upgrade to the fixed release
cd /var/www/froxlor && git fetch --tags && git checkout 2.3.12
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.