Froxlor has an authorization bypass in FTP shell assignment via missing server-side `available_shells` enforcement
Published Jun 4, 2026
8.6
HIGHCVSS 4.0
EPSS 0.36%
Description
Froxlor is open source server administration software. Version 2.3.6 lets administrators configure `system.available_shells` as the approved shell list that customers may assign to FTP users. However, the server-side FTP account handlers do not enforce that whitelist when processing add or edit requests. As a result, an authenticated customer with shell delegation enabled can submit an arbitrary shell such as `/bin/bash` even when the panel UI only offers more restricted choices. In deployments that use the default `nssextrausers` integration, the attacker-controlled shell is then propagated into the system account database, leading to real host shell access. Version 2.3.7 fixes the issue.
Affected products
-
- Version = 2.3.6StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34314 Advisory
- https://github.com/advisories/GHSA-gcv3-5v9q-fmhh Advisory
- https://github.com/froxlor/froxlor/releases/tag/2.3.7 x_refsource_MISC
- https://github.com/froxlor/froxlor/security/advisories/GHSA-gcv3-5v9q-fmhh exploitx_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-41235
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-34314 | Advisory | |
| https://github.com/advisories/GHSA-gcv3-5v9q-fmhh | Advisory | |
| https://github.com/froxlor/froxlor/releases/tag/2.3.7 | x_refsource_MISC | |
| https://github.com/froxlor/froxlor/security/advisories/GHSA-gcv3-5v9q-fmhh | exploitx_refsource_CONFIRM | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-41235 |
Change history (0)
No recorded changes yet.