CVE-2026-100711: Froxlor

High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.

froxlor versions before 2.3.12 fail to invalidate existing panel sessions, API keys, and 2FA trust cookies when a user password is changed. Attackers holding hijacked sessions, valid API keys, or 2FA trust tokens retain full account access after password rotation, bypassing incident response actions.

Affected products

  • Froxlor Froxlor: before 2.3.12 (fixed in 2.3.12)

Published 2026-09-26. Last modified 2026-09-28.