CVE-2026-100719: Froxlor

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

Froxlor versions before 2.3.12 contain a credential disclosure vulnerability in the DirProtections.listing API command that returns htpasswd password hashes. Authenticated API users can retrieve bcrypt password hashes for protected-directory users, enabling offline cracking attempts and exposure of reused credentials.

Affected products

  • Froxlor Froxlor: before 2.3.12 (fixed in 2.3.12)

Published 2026-09-26. Last modified 2026-09-26.