froxlor versions before 2.3.12 fail to invalidate existing panel sessions, API keys, and 2FA trust cookies when a user password is changed. Attackers holding hijacked sessions, valid API keys, or 2FA trust tokens retain full account access after password rotation, bypassing incident response actions.
froxlor before 2.3.12 Authentication Bypass via Session Persistence
Problem type
Affected products
froxlor
< 2.3.12 - AFFECTED
2.3.12 - UNAFFECTED
References
https://github.com/froxlor/froxlor/security/advisories/GHSA-57wv-g7m3-hmff
https://www.vulncheck.com/advisories/froxlor-before-2.3.12-authentication-bypass-via-session-persistence
GitHub Security Advisories
GHSA-xf4r-hwm6-xhx6
froxlor versions before 2.3.12 fail to invalidate existing panel sessions, API keys, and 2FA...
https://github.com/advisories/GHSA-xf4r-hwm6-xhx6froxlor versions before 2.3.12 fail to invalidate existing panel sessions, API keys, and 2FA trust cookies when a user password is changed. Attackers holding hijacked sessions, valid API keys, or 2FA trust tokens retain full account access after password rotation, bypassing incident response actions.
https://github.com/froxlor/froxlor/security/advisories/GHSA-57wv-g7m3-hmff
https://nvd.nist.gov/vuln/detail/CVE-2026-100711
https://www.vulncheck.com/advisories/froxlor-before-2.3.12-authentication-bypass-via-session-persistence
https://github.com/advisories/GHSA-xf4r-hwm6-xhx6
JSON source
https://cveawg.mitre.org/api/cve/CVE-2026-100711Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-100711",
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"dateUpdated": "2026-09-26T13:24:04.358Z",
"dateReserved": "2026-09-26T02:40:23.372Z",
"datePublished": "2026-09-26T13:24:04.358Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck",
"dateUpdated": "2026-09-26T13:24:04.358Z"
},
"datePublic": "2026-09-06T00:00:00.000Z",
"title": "froxlor before 2.3.12 Authentication Bypass via Session Persistence",
"descriptions": [
{
"lang": "en",
"value": "froxlor versions before 2.3.12 fail to invalidate existing panel sessions, API keys, and 2FA trust cookies when a user password is changed. Attackers holding hijacked sessions, valid API keys, or 2FA trust tokens retain full account access after password rotation, bypassing incident response actions."
}
],
"affected": [
{
"vendor": "froxlor",
"product": "froxlor",
"defaultStatus": "unaffected",
"versions": [
{
"version": "0",
"status": "affected",
"versionType": "semver",
"lessThan": "2.3.12"
},
{
"version": "2.3.12",
"status": "unaffected",
"versionType": "semver"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "Insufficient Session Expiration",
"cweId": "CWE-613",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://github.com/froxlor/froxlor/security/advisories/GHSA-57wv-g7m3-hmff",
"name": "GitHub Security Advisory (GHSA-57wv-g7m3-hmff)",
"tags": [
"vendor-advisory"
]
},
{
"url": "https://www.vulncheck.com/advisories/froxlor-before-2.3.12-authentication-bypass-via-session-persistence",
"name": "VulnCheck Advisory: froxlor before 2.3.12 Authentication Bypass via Session Persistence",
"tags": [
"third-party-advisory"
]
}
],
"metrics": [
{
"format": "CVSS"
},
{
"format": "CVSS",
"cvssV3_1": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 7.5,
"baseSeverity": "HIGH"
}
}
],
"credits": [
{
"lang": "en",
"value": "skeletonsec",
"type": "reporter"
}
]
}
}
}