CVE-2026-90935: Froxlor before 2.3.7 Authorization Bypass via Mysqls.add API

Published Sep 14, 2026
·
Updated

Froxlor before 2.3.7 fails to validate the mysqlserver parameter against a customer's allowedmysqlserver allowlist in the Mysqls.add API command. Attackers can supply a disallowed server index to create MySQL databases and users on forbidden servers, bypassing per-customer access controls.

Affected Software

1 affected component
Froxlor Froxlor<2.3.7

Event History

Sep 14, 2026
CVE Published
via MITRE·12:48 PM
Data Sourced
via MITRE·12:48 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker needs customer-level privileges sufficient to invoke the Mysqls.add API command. The issue is remotely reachable and does not require user interaction.

2

What access can an attacker gain through the bypass?

They can provide a MySQL server index that is not in their allowed_mysqlserver allowlist, then create MySQL databases and users on servers that should be forbidden to that customer.

3

Which deployments are affected?

Froxlor versions before 2.3.7 are affected. The provided data does not indicate whether any particular default customer configuration grants access to the vulnerable API command.

4

How can I determine whether this has been exploited?

Review Mysqls.add API activity and MySQL database or user creation records for customer accounts. Look for creations assigned to MySQL server indexes outside the requesting customer's allowed_mysqlserver allowlist.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203