CVE-2026-100708: Froxlor before 2.3.13 Private Key Disclosure via Certificates API

Published Sep 26, 2026
·
Updated

Froxlor before 2.3.13 returns the sslkeyfile column — which stores the raw PEM TLS private-key content — verbatim in the JSON responses of the Certificates.get and Certificates.listing API commands, because the results of the underlying domainsslsettings queries are passed through ApiCommand::response() without any field stripping or allowlist. A low-privileged authenticated customer API caller can retrieve the private keys of their own domains' certificates, including Let's Encrypt keys that Froxlor generates server-side and stores root-only (0600) and to which the customer otherwise has no filesystem access; reseller and customersseeall admin accounts can dump the private keys of other principals through the same sink. Disclosed keys enable domain impersonation, passive decryption of captured TLS traffic, and active machine-in-the-middle attacks.

Affected Software

1 affected component
Froxlor Froxlor<2.3.13

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Froxlor to a version that resolves this vulnerability.

    Fixed in 2.3.13

Event History

Sep 26, 2026
CVE Published
via MITRE·01:24 PM
Data Sourced
via MITRE·01:24 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which authenticated users can retrieve private keys through the affected API?

A low-privileged customer API caller can retrieve the private keys for certificates belonging to their own domains. Resellers and customers_see_all administrator accounts can retrieve private keys belonging to other principals.

2

Does protecting the key files on disk prevent this disclosure?

No. The issue exposes the raw PEM content through JSON API responses, including Let's Encrypt keys that are stored root-only with 0600 permissions and would otherwise be inaccessible to the customer through the filesystem.

3

What access does an attacker need to exploit this?

The attacker needs an authenticated API account with at least customer-level privileges and must be able to invoke the Certificates.get or Certificates.listing API commands. No user interaction is required.

4

How can an administrator check for exposure?

Review responses from Certificates.get and Certificates.listing for an ssl_key_file field containing PEM private-key material. Accounts with reseller or customers_see_all access require particular review because they can access keys for other principals.

5

Which deployments are affected?

Froxlor versions before 2.3.13 are affected. The disclosed material includes private keys generated and stored by Froxlor for domain certificates.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203