CVE-2026-26279CWE-482CWE-78

Froxlor Admin-to-Root Privilege Escalation via Input Validation Bypass + OS Command Injection

Critical · published March 3, 2026

CVSS v3.1
9.1
EPSS
1%
Percentile
54.3
In the wild
Unconfirmed
What it is

Froxlor is open source server administration software. Prior to 2.3.4, a typo in Froxlor's input validation code (== instead of =) completely disables email format checking for all settings fields declared as email type. This allows an authenticated admin to store arbitrary strings in the panel.adminmail setting. This value is later concatenated into a shell command executed as root by a cron job, where the pipe character | is explicitly whitelisted. The result is full root-level Remote Code Execution. This vulnerability is fixed in 2.3.4.

The record
Technical detail
CVSS v3.1
9.1 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00802 · 54.3th percentile
Weaknesses
CWE-482 · Comparing instead of Assigning; CWE-78 · Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Published
2026-03-03T22:31Z
EPSS history
Timeline
  • 03 MAR 22:31Z
    Froxlor Admin-to-Root Privilege Escalation via Input Validation Bypass + OS Command Injection
    cvelistv5