Skip to main content
Vulnerability Database/CVE-2026-100718

CVE-2026-100718: Froxlor Authentication Bypass Vulnerability

CVE-2026-100718 is an authentication bypass flaw in Froxlor that allows customers to register unauthorized external sender addresses despite policy restrictions. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-100718 Overview

CVE-2026-100718 affects Froxlor server management panel versions through 2.3.10. The vulnerability resides in the EmailSender.add API command, which fails to enforce the mail.allow_external_domains policy. An authenticated customer with API access can register arbitrary external sender addresses even when administrators have explicitly disabled external allowed-sender domains. The flaw creates a configuration bypass between the administrative UI and the API layer, enabling sender spoofing where downstream mail configuration consumes the allowed-sender table. Froxlor developers resolved the issue in version 2.3.12.

Critical Impact

Authenticated Froxlor customers can bypass administrator-configured mail policy to authorize arbitrary sender identities, enabling email spoofing from domains the customer does not own.

Affected Products

  • Froxlor server management panel versions through 2.3.10
  • Froxlor deployments where mail.enable_allow_sender = 1 and mail.allow_external_domains = 0
  • Froxlor installations whose generated mail configuration consumes the allowed-sender table

Discovery Timeline

  • 2026-09-26 - CVE-2026-100718 published to NVD
  • 2026-09-26 - Last updated in NVD database

Technical Details for CVE-2026-100718

Vulnerability Analysis

Froxlor exposes mail configuration policies that let administrators restrict which sender addresses customers can authorize for outbound mail. Two settings govern this behavior: mail.enable_allow_sender activates the allowed-sender feature, and mail.allow_external_domains controls whether sender addresses outside the customer's hosted domains are permitted. The administrative UI honors both settings. The EmailSender.add API command checks only the first setting and silently accepts external sender addresses regardless of the second. Any authenticated customer with API access can submit a request that stores an arbitrary external email address in the allowed-sender table.

Root Cause

The root cause is incorrect default permissions in the API handler [CWE-276]. The server-side validation logic for EmailSender.add omits the mail.allow_external_domains check that the UI enforces. This inconsistency between enforcement layers allows API consumers to bypass restrictions that administrators believe are in effect.

Attack Vector

Exploitation requires valid customer-level credentials and network access to the Froxlor API endpoint. The attacker invokes EmailSender.add with a sender address outside their hosted domains. The record persists in the allowed-sender table and, when the mail server consumes that table, the attacker can send mail using the spoofed identity. Technical details are documented in the GitHub Security Advisory GHSA-m9j6-9856-68xf and the Vulncheck Froxlor Authentication Bypass Advisory.

Detection Methods for CVE-2026-100718

Indicators of Compromise

  • Entries in the Froxlor allowed-sender database table containing email addresses outside domains owned by the associated customer account
  • API access logs showing EmailSender.add calls from customer accounts followed by outbound mail using non-customer domains
  • Outbound mail server logs recording successful authenticated submissions where the envelope sender does not match any hosted domain tied to the authenticating customer

Detection Strategies

  • Query the Froxlor panel_mail_allowed_sender records and cross-reference each sender address against the customer's hosted domain list to flag mismatches
  • Alert on EmailSender.add API invocations when the submitted address domain is not present in the customer's domain inventory
  • Correlate SMTP submission logs with allowed-sender table changes to identify spoofed message campaigns

Monitoring Recommendations

  • Enable verbose API request logging on the Froxlor instance and forward records to a centralized log platform for retention and search
  • Monitor SMTP authentication logs for sender addresses that do not align with the authenticated customer identity
  • Track configuration drift between the mail.allow_external_domains setting and the actual contents of the allowed-sender table

How to Mitigate CVE-2026-100718

Immediate Actions Required

  • Upgrade all Froxlor installations to version 2.3.12 or later, which contains the fix
  • Audit the allowed-sender table for existing entries that reference domains outside customer-owned domains and remove unauthorized records
  • Rotate or revoke API credentials for customer accounts suspected of abusing the EmailSender.add endpoint

Patch Information

Froxlor version 2.3.12 enforces the mail.allow_external_domains policy in the EmailSender.add API command. Administrators should obtain the release from the official Froxlor repository and follow standard upgrade procedures. Review the GitHub Security Advisory GHSA-m9j6-9856-68xf for upstream patch references.

Workarounds

  • Temporarily disable the allowed-sender feature by setting mail.enable_allow_sender = 0 until the upgrade can be completed
  • Restrict API access at the network layer so only trusted hosts can reach the Froxlor API endpoints
  • Configure the mail server to perform independent sender authorization checks rather than trusting the Froxlor-generated allowed-sender list
bash
# Configuration example
# Disable allowed-sender feature pending upgrade to Froxlor 2.3.12
# Set in Froxlor admin: System > Settings > Email
mail.enable_allow_sender = 0

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.