Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing customers to inject arbitrary lines into authorized_keys files. Attackers can inject malicious SSH key entries with option directives to gain persistent unauthorized access that survives key deletion and SSH access revocation.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 13 Sep 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing customers to inject arbitrary lines into authorized_keys files. Attackers can inject malicious SSH key entries with option directives to gain persistent unauthorized access that survives key deletion and SSH access revocation. | |
| Title | Froxlor before 2.3.12 SSH Key Injection via authorized_keys | |
| First Time appeared |
Froxlor
Froxlor froxlor |
|
| Weaknesses | CWE-93 | |
| CPEs | cpe:2.3:a:froxlor:froxlor:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Froxlor
Froxlor froxlor |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-13T10:45:37.369Z
Reserved: 2026-09-13T10:14:51.758Z
Link: CVE-2026-90767
No data.
Status : Received
Published: 2026-09-13T11:17:00.947
Modified: 2026-09-13T11:17:00.947
Link: CVE-2026-90767
No data.
OpenCVE Enrichment
Updated: 2026-09-13T13:45:17Z
Weaknesses