CVE-2026-100711 Details
Description
froxlor versions before 2.3.12 fail to invalidate existing panel sessions, API keys, and 2FA trust cookies when a user password is changed. Attackers holding hijacked sessions, valid API keys, or 2FA trust tokens retain full account access after password rotation, bypassing incident response actions.
A vulnerability exists in Froxlor versions prior to 2.3.12, where changing a user's password does not invalidate active panel sessions, API keys, or 2FA trust cookies. This oversight allows attackers with hijacked sessions, valid API keys, or 2FA trust tokens to maintain full access to the account even after the password has been changed, effectively bypassing incident response measures.
After a password change, invalidate all other sessions, revoke or rotate API keys, and purge 2FA trust tokens. Additionally, consider implementing a per-user credential epoch stored in the session for validation.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/froxlor/froxlor/security/advisories/GHSA-57wv-g7m3-hmff | [email protected] | AdvisoryExploitRemedyVendor |
| https://www.vulncheck.com/advisories/froxlor-before-2.3.12-authentication-bypass-via-session-persistence | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-613 | Insufficient Session Expiration | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| froxlor | <= 2.3.10 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 26, 2026 | New CVE Received | [email protected] |
Volerion