CVE-2026-100711 - froxlor before 2.3.12 Authentication Bypass via Session Persistence
CVE ID :CVE-2026-100711
Published : Sept. 26, 2026, 2:16 p.m. | 2 hours, 54 minutes ago
Description :froxlor versions before 2.3.12 fail to invalidate existing panel sessions, API keys, and 2FA trust cookies when a user password is changed. Attackers holding hijacked sessions, valid API keys, or 2FA trust tokens retain full account access after password rotation, bypassing incident response actions.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 26, 2026, 2:16 p.m. | 2 hours, 54 minutes ago
Description :froxlor versions before 2.3.12 fail to invalidate existing panel sessions, API keys, and 2FA trust cookies when a user password is changed. Attackers holding hijacked sessions, valid API keys, or 2FA trust tokens retain full account access after password rotation, bypassing incident response actions.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...