Junglewise Threat Intelligence

CVE-2026-100718: Froxlor API policy bypass in EmailSender.add

CVE-2026-100718 · Severity: high · CVSS 7.1 · Published 2026-09-26

Technologies: Froxlor. Vendors: Froxlor.

Executive brief

Froxlor is a hosting control panel that manages email accounts and sender authentication policies. In versions through 2.3.10, the EmailSender.add API command fails to enforce the administrator's restriction on external sender domains, allowing a customer with API access to register arbitrary sender addresses outside their hosted domains. This enables sender spoofing and circumvents email security policies the administrator explicitly configured.

Technical details

The vulnerability is an authorization bypass (CWE-276) where the EmailSender.add API endpoint does not validate the mail.allow_external_domains policy setting before accepting external sender identities. An authenticated customer with API access can add external sender addresses to their mailbox despite the global policy mail.allow_external_domains = 0 being set. The fix is available in version 2.3.12.

Affected products

  • Froxlor Froxlor through 2.3.10

Timeline

  • 2026-09-26: disclosed
  • 2026-09-26: patched: Fixed in version 2.3.12

References

Related threats