CVE-2026-100715: Froxlor before 2.3.12 Arbitrary File Deletion via Symlink

Published Sep 26, 2026
·
Updated

Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via symlink following in the FTP data deletion cron task. Cron task 8 (deleteFtpData), queued when an FTP account is deleted, calls FileDir::makeCorrectDir() without the $fixedhomedir argument, so the symlink component walk is skipped, and then executes 'rm -rf' as root on the resulting path with string-level guards only. Because makeCorrectDir() appends a trailing slash, GNU rm dereferences a symlink used either as an intermediate path component or as the final component. An authenticated customer who can write to the FTP home directory can plant a symlink between task insertion and cron execution, causing the root cron job to recursively delete arbitrary directory trees, resulting in cross-tenant data destruction and host denial of service. This issue is fixed in Froxlor 2.3.12.

Affected Software

1 affected component
Froxlor Froxlor<2.3.12

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Froxlor to a version that resolves this vulnerability.

    Fixed in 2.3.12

Event History

Sep 26, 2026
CVE Published
via MITRE·01:24 PM
Data Sourced
via MITRE·01:24 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue in practice?

An authenticated Froxlor customer who can write to an FTP home directory can exploit it. The attack targets the interval after an FTP account deletion queues the cleanup task and before the root-run cron task executes it.

2

Are default deployments affected?

Deployments running Froxlor through 2.3.10 are affected when the FTP data deletion cron task is used. The vulnerable cleanup task is queued when an FTP account is deleted and runs rm -rf as root.

3

What is the impact of successful exploitation?

An attacker can cause the root cron job to recursively delete arbitrary directory trees by placing a symlink in the FTP home directory. This can destroy data belonging to other tenants and cause host denial of service.

4

What should be done if upgrading is not immediately possible?

Prevent untrusted customers from writing to FTP home directories and avoid deleting FTP accounts in a way that queues the affected cleanup task until remediation is available. Review queued FTP deletion tasks and their referenced paths before allowing the cron task to run.

5

How can administrators determine whether they are affected?

Check the installed Froxlor version and upgrade to 2.3.12, which fixes the issue. Systems running through 2.3.10 should be treated as vulnerable, particularly if FTP account deletion queues cron task 8, deleteFtpData.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203