CVE-2026-90767: Froxlor before 2.3.12 SSH Key Injection via authorized_keys
Published Sep 13, 2026
·Updated
Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing customers to inject arbitrary lines into authorizedkeys files. Attackers can inject malicious SSH key entries with option directives to gain persistent unauthorized access that survives key deletion and SSH access revocation.
Affected Software
1 affected component
Froxlor Froxlor<2.3.12
Event History
Sep 13, 2026
CVE Published
via MITRE·10:45 AM
Data Sourced
via MITRE·10:45 AM
DescriptionSeverityWeakness