HIGH 8.7 NVD
CVE-2026-100711
froxlor versions before 2.3.12 fail to invalidate existing panel sessions, API keys, and 2FA trust cookies when a user password is changed. Attackers holding hi
froxlor versions before 2.3.12 fail to invalidate existing panel sessions, API keys, and 2FA trust cookies when a user password is changed. Attackers holding hijacked sessions, valid API keys, or 2FA trust tokens retain full account access after password rotation, bypassing incident response actions.
References
- https://github.com/froxlor/froxlor/security/advisories/GHSA-57wv-g7m3-hmff
- https://www.vulncheck.com/advisories/froxlor-before-2.3.12-authentication-bypass-via-sessi
This high severity vulnerability with a CVSS score of 8.7 was published on 2026-09-26 via NVD.
vulnfeed aggregates 11675 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.