Froxlor before 2.3.12 does not restrict or escape the system.letsencryptchallengepath setting: unlike sibling settings hardened in GHSA-33mp, the… (CVE-2026-100714)
Froxlor versions up to and including 2.3.10 have a critical vulnerability where the system.letsencryptchallengepath setting is not properly restricted or escaped. This allows an administrator or any actor able to write settings to inject arbitrary command-line options into the acme.sh command executed by root via cron, leading to arbitrary command execution or file writes as root. The issue is fixed in version 2.3.12.
AI Analysis
Technical Summary
Froxlor before version 2.3.12 does not properly restrict or escape the system.letsencryptchallengepath setting. Unlike other similar settings hardened in GHSA-33mp, this field lacks string_regexp or required_otp guards. Its value is concatenated unescaped into the acme.sh command line in lib/Froxlor/Cron/Http/LetsEncrypt/AcmeSh.php and executed by root cron via FileDir::safe_exec. The safe_exec function blacklists certain shell metacharacters but allows spaces and quotes, enabling word splitting into additional acme.sh arguments. An attacker with permission to write settings (e.g., through the settings-import API) can inject options like --renew-hook, --pre-hook, or --post-hook to execute arbitrary commands as root during the next Let's Encrypt cron run, or use --config-home/--cert-home for arbitrary file writes. Versions up to and including 2.3.10 are affected; the vulnerability is fixed in 2.3.12.
Potential Impact
An attacker with the ability to modify Froxlor settings can achieve arbitrary command execution as root or arbitrary file writes on the affected system. This can lead to full system compromise, data loss, or persistent unauthorized access. The vulnerability is critical with a CVSS score of 9.1, reflecting high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
Upgrade Froxlor to version 2.3.12 or later, where this vulnerability is fixed. Until then, restrict access to the settings-import API and any administrative interfaces that allow modification of the system.letsencryptchallengepath setting to trusted users only. Monitor for unauthorized changes to settings. Patch status is confirmed fixed in 2.3.12.
Froxlor before 2.3.12 does not restrict or escape the system.letsencryptchallengepath setting: unlike sibling settings hardened in GHSA-33mp, the… (CVE-2026-100714)
Description
Froxlor versions up to and including 2.3.10 have a critical vulnerability where the system.letsencryptchallengepath setting is not properly restricted or escaped. This allows an administrator or any actor able to write settings to inject arbitrary command-line options into the acme.sh command executed by root via cron, leading to arbitrary command execution or file writes as root. The issue is fixed in version 2.3.12.
CVSS v3.1
Score 9.1critical
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Froxlor before version 2.3.12 does not properly restrict or escape the system.letsencryptchallengepath setting. Unlike other similar settings hardened in GHSA-33mp, this field lacks string_regexp or required_otp guards. Its value is concatenated unescaped into the acme.sh command line in lib/Froxlor/Cron/Http/LetsEncrypt/AcmeSh.php and executed by root cron via FileDir::safe_exec. The safe_exec function blacklists certain shell metacharacters but allows spaces and quotes, enabling word splitting into additional acme.sh arguments. An attacker with permission to write settings (e.g., through the settings-import API) can inject options like --renew-hook, --pre-hook, or --post-hook to execute arbitrary commands as root during the next Let's Encrypt cron run, or use --config-home/--cert-home for arbitrary file writes. Versions up to and including 2.3.10 are affected; the vulnerability is fixed in 2.3.12.
Potential Impact
An attacker with the ability to modify Froxlor settings can achieve arbitrary command execution as root or arbitrary file writes on the affected system. This can lead to full system compromise, data loss, or persistent unauthorized access. The vulnerability is critical with a CVSS score of 9.1, reflecting high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
Upgrade Froxlor to version 2.3.12 or later, where this vulnerability is fixed. Until then, restrict access to the settings-import API and any administrative interfaces that allow modification of the system.letsencryptchallengepath setting to trusted users only. Monitor for unauthorized changes to settings. Patch status is confirmed fixed in 2.3.12.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-fh3h-q9pj-x5qp
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-100714"]
- Database Specific Severity
- CRITICAL
- Cvss Version
- 3.1
Threat ID: 6ab89bd7f7a7c54106941ff5
Added to database: 09/27/2026, 04:30:15 UTC
Last enriched: 09/27/2026, 04:40:51 UTC
Last updated: 09/28/2026, 01:47:40 UTC
Views: 18
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.