Junglewise Threat Intelligence

CVE-2026-90767: Froxlor SSH public key injection in SshKeys::add()

CVE-2026-90767 · Severity: medium · CVSS 6.5 · Published 2026-09-13

Technologies: Froxlor. Vendors: Froxlor.

Executive brief

Froxlor is a web-based server administration panel used to manage hosting and mail services. A flaw in how it validates SSH public keys allows customers with valid access to inject arbitrary lines into SSH authorized_keys files, potentially creating persistent backdoors that survive key deletions and access revocation. This could allow attackers to maintain unauthorized remote access to server accounts.

Technical details

Froxlor before version 2.3.12 fails to properly validate multi-line SSH public keys submitted via the SshKeys::add() API endpoint. The vulnerability is a line injection flaw where attackers with valid customer account access can include newline characters and option directives in SSH key submissions to inject malicious entries into authorized_keys files. By embedding SSH key options (such as command restrictions or forced command execution), attackers can establish persistent access that persists even after the original key is deleted or SSH access is administratively revoked. The fix is available in version 2.3.12 or later.

Affected products

  • Froxlor Froxlor before 2.3.12

Timeline

  • 2026-09-13: disclosed

References

Related threats