CVE-2026-100711: froxlor before 2.3.12 Authentication Bypass via Session Persistence
froxlor versions before 2.3.12 fail to invalidate existing panel sessions, API keys, and 2FA trust cookies when a user password is changed. Attackers holding hijacked sessions, valid API keys, or 2FA trust tokens retain full account access after password rotation, bypassing incident response actions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
froxlorto a version that resolves this vulnerability.Fixed in 2.3.12
Event History
Frequently Asked Questions
Who is exposed to this issue?
Froxlor deployments running a version before 2.3.12 are affected. Accounts are at risk if an attacker already possesses a hijacked panel session, a valid API key, or a trusted 2FA cookie for that account.
What does an attacker need to retain access after a password reset?
The attacker needs a previously obtained valid session, API key, or 2FA trust token. No further authentication or user interaction is required to continue using that credential after the password is changed.
Does changing the affected user's password remove an attacker's access?
No. In affected versions, password changes do not invalidate existing panel sessions, API keys, or 2FA trust cookies, so password rotation alone does not terminate access held through those artifacts.
How can administrators tell whether an account may still be compromised after a password change?
Treat accounts as potentially still exposed when their password was changed after suspected session, API key, or 2FA trust-token theft. The provided information does not identify a detection method for confirming which existing artifacts were used.