Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100708— Froxlor before 2.3.13 Private Key Disclosure via Certificates API

Quick assessment

Affected
froxlor froxlor
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Froxlor 2.3.13 版本之前, 和 API 命令的 JSON 响应中会原样返回 列,该列存储的是原始的 PEM 格式 TLS 私钥内容。这是因为底层查询 的结果直接通过 方法返回,未进行任何字段过滤或白名单限制。具有低权限的认证 API 调用者可以获取其所属域名的证书私钥,包括由 Froxlor 在服务器端生成并以 root 权限(权限设置为 0600)存储的 Let's Encrypt 私钥,而普通用户通常无法直接访问文件系统获取这些文件;此外,拥有 reseller 权限或具有 权限的管理员账户可

CVSS 7.1 · High EPSS 0.13% · P2
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100708

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Froxlor before 2.3.13 Private Key Disclosure via Certificates API
Source: CVE Program / CVE List V5
Vulnerability Description
Froxlor before 2.3.13 returns the ssl_key_file column — which stores the raw PEM TLS private-key content — verbatim in the JSON responses of the Certificates.get and Certificates.listing API commands, because the results of the underlying domain_ssl_settings queries are passed through ApiCommand::response() without any field stripping or allowlist. A low-privileged authenticated customer API caller can retrieve the private keys of their own domains' certificates, including Let's Encrypt keys that Froxlor generates server-side and stores root-only (0600) and to which the customer otherwise has no filesystem access; reseller and customers_see_all admin accounts can dump the private keys of other principals through the same sink. Disclosed keys enable domain impersonation, passive decryption of captured TLS traffic, and active machine-in-the-middle attacks.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
信息暴露
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
froxlor froxlor 0 ~ 2.3.13 -

II. Public POCs for CVE-2026-100708

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100708

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-100708 (1)

Other References for CVE-2026-100708 (1)

Same Patch Batch · froxlor · 2026-09-26 · 13 CVEs total

CVE-2026-100717 9.9 CRITICAL froxlor before 2.3.12 CRLF Injection via validateUrl userinfo
CVE-2026-100716 9.9 CRITICAL Froxlor before 2.3.12 Privilege Escalation via Symlink
CVE-2026-100715 9.6 CRITICAL Froxlor before 2.3.12 Arbitrary File Deletion via Symlink
CVE-2026-100714 9.1 CRITICAL Froxlor before 2.3.12 Command Injection via letsencryptchallengepath
CVE-2026-100720 8.7 HIGH Froxlor before 2.3.12 Stored XSS via SSL certificate issuer
CVE-2026-100713 7.8 HIGH Froxlor before 2.3.12 Privilege Escalation via SSH Key Sync
CVE-2026-100711 7.5 HIGH froxlor before 2.3.12 Authentication Bypass via Session Persistence
CVE-2026-100709 7.5 HIGH Froxlor before 2.3.12 2FA Bypass via Namespace Confusion
CVE-2026-100718 7.1 HIGH Froxlor before 2.3.12 Authentication Bypass via EmailSender.add
CVE-2026-100712 6.5 MEDIUM froxlor before 2.3.12 Two-Factor Authentication Bypass via CSRF
CVE-2026-100719 6.5 MEDIUM Froxlor before 2.3.12 Credential Disclosure via DirProtections API
CVE-2026-100710 4.9 MEDIUM Froxlor before 2.3.12 DKIM Private Key Disclosure via API

IV. Related Vulnerabilities

V. Comments for CVE-2026-100708

No comments yet


Leave a comment