CVE-2026-100711
Last modified
CVE-2026-100711 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. froxlor versions before 2.3.12 fail to invalidate existing panel sessions, API keys, and 2FA trust cookies when a user password is changed. Attackers holding hijacked sessions, valid API keys, or 2FA trust tokens retain full account access after password rotation, bypassing incident response actions..
Description
froxlor versions before 2.3.12 fail to invalidate existing panel sessions, API keys, and 2FA trust cookies when a user password is changed. Attackers holding hijacked sessions, valid API keys, or 2FA trust tokens retain full account access after password rotation, bypassing incident response actions.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-100711?
How severe is CVE-2026-100711?
How do I fix CVE-2026-100711?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-100706kyverno before 1.19.1 fails to properly validate URL-encoded…9.9
- CVE-2026-100707Kyverno before 1.19.1 contains a namespace isolation bypass …7.7
- CVE-2026-100708Froxlor before 2.3.13 returns the ssl_key_file column — whic…7.1
- CVE-2026-100709Froxlor through 2.3.10 stores only a numeric user ID in reme…7.5
- CVE-2026-10071DreamMaker developed by Interinfo has an Arbitrary File Uplo…9.8
- CVE-2026-100710Froxlor through 2.3.10 does not filter sensitive columns fro…4.9
- CVE-2026-100712froxlor through 2.3.10 disables a user's two-factor authenti…6.5
- CVE-2026-100713Froxlor 2.3.10 and earlier contain a time-of-check time-of-u…7.8
- CVE-2026-100714Froxlor before 2.3.12 does not restrict or escape the system…9.1
- CVE-2026-100715Froxlor through 2.3.10 is vulnerable to arbitrary file delet…9.6
- CVE-2026-100716Froxlor is a server administration panel. In versions 2.3.10…9.9
- CVE-2026-100717froxlor is a server administration panel. In versions 2.3.10…9.9
Are you affected by CVE-2026-100711?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
