Junglewise Threat Intelligence

CVE-2026-100709: Froxlor TOTP bypass via 2FA token namespace confusion

CVE-2026-100709 · Severity: high · CVSS 7.5 · Published 2026-09-26

Technologies: Froxlor. Vendors: Froxlor.

Executive brief

Froxlor is a web hosting control panel that manages customer and administrator accounts. An attacker who knows an administrator's password and controls a customer account with a matching numeric ID can bypass the administrator's two-factor authentication (TOTP) by reusing the customer's remembered 2FA token, gaining full administrative access to the panel including all customer data and configuration.

Technical details

The panel_2fa_tokens table stores only a numeric user ID without recording whether the token belongs to a customer or administrator account, despite these IDs being allocated from separate namespaces. During login, the remembered-token lookup does not constrain results to the account type being authenticated, allowing a customer token with ID N to satisfy authentication for an administrator with ID N. The vulnerability requires the attacker to already possess both the target administrator's password and a valid remembered 2FA cookie from a customer account with a colliding ID; it is a second-factor bypass that does not defeat password authentication. The vulnerability is fixed in version 2.3.12.

Affected products

  • Froxlor Froxlor through 2.3.10

Timeline

  • 2026-09-26: disclosed
  • 2026-09-26: patched: fixed in version 2.3.12

References

Related threats