Description
Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing customers to inject arbitrary lines into authorized_keys files. Attackers can inject malicious SSH key entries with option directives to gain persistent unauthorized access that survives key deletion and SSH access revocation.
Published: 2026-09-13
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Persistent Unauthorized Access via SSH Key Injection
Action: Apply Patch
AI Analysis

Impact

Froxlor versions earlier than 2.3.12 accept multi‑line SSH public keys sent to the SshKeys::add() endpoint without proper validation, letting an attacker append arbitrary lines to any user’s authorized_keys file. By inserting SSH option directives, the injected key can remain active even after the original key is removed or the user’s normal SSH access is revoked, allowing a persistent foothold in the system.

Affected Systems

Every installation of Froxlor running any release before 2.3.12 is affected. The vulnerability is fixed only in version 2.3.12 and later.

Risk and Exploitability

The CVSS score of 7.1 classifies the flaw as high severity, while the EPSS score of < 1% indicates a low baseline probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack requires the ability to reach the SshKeys:: authenticated user with permission to add SSH keys. Once a malicious line is written to a user’s authorized_keys file, it persists through normal key‑management operations, enabling long‑term unauthorized access.

Generated by OpenCVE AI on September 15, 2026 at 17:00 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Frox or later to apply the fixed input‑validation in the SshKeys::add() endpoint.
  • Restrict access to the Froxlor API so that only trusted administrators can add SSH keys, ensuring that only privileged accounts can perform key‑management operations.
  • Audit the authorized_keys files on managed hosts regularly, scanning for anomalous lines or option directives that could indicate a prior injection attempt.

Generated by OpenCVE AI on September 15, 2026 at 17:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing customers to inject arbitrary lines into authorized_keys files. Attackers can inject malicious SSH key entries with option directives to gain persistent unauthorized access that survives key deletion and SSH access revocation.
Title Froxlor before 2.3.12 SSH Key Injection via authorized_keys
First Time appeared Froxlor
Froxlor froxlor
Weaknesses CWE-93
CPEs cpe:2.3:a:froxlor:froxlor:*:*:*:*:*:*:*:*
Vendors & Products Froxlor
Froxlor froxlor
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:21:48.328Z

Reserved: 2026-09-13T10:14:51.758Z

Link: CVE-2026-90767

cve-icon Vulnrichment

Updated: 2026-09-14T17:42:26.332Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T11:17:00.947

Modified: 2026-09-23T17:17:44.313

Link: CVE-2026-90767

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:15:14Z

Weaknesses
  • CWE-93

    Improper Neutralization of CRLF Sequences ('CRLF Injection')