PatchSiren cyber security CVE debrief
CVE-2026-62988 froxlor CVE debrief
The Froxlor server administration software has a critical vulnerability (CVE-2026-62988) that exposes sensitive information through its API commands for customers, admins, and FTP users. An authenticated API caller can obtain full database rows, including password hashes and Base32-encoded TOTP seeds, which can be used to crack passwords offline and generate valid second-factor codes. This issue is fixed in version 2.3.8. System administrators using Froxlor should be aware of this vulnerability and take immediate action to protect their systems by reviewing and restricting API permissions, implementing additional monitoring, updating to version 2.3.8 or later, rotating passwords and TOTP seeds for affected accounts, and enabling two-factor authentication for all accounts.
- Vendor
- froxlor
- Product
- Unknown
- CVSS
- CRITICAL 9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-18
- Original CVE updated
- 2026-09-08
- Advisory published
- 2026-08-18
- Advisory updated
- 2026-09-08
Who should care
System administrators using Froxlor server administration software, especially those with API integrations or exposed instances, should be aware of this vulnerability and take immediate action to protect their systems. This includes reviewing and restricting API permissions, implementing additional monitoring, updating to version 2.3.8 or later, rotating passwords and TOTP seeds for affected accounts, and enabling two-factor authentication for all accounts. Additionally, security teams and vulnerability management teams should prioritize this vulnerability due to its critical severity and potential impact on hosting panel or hosted resources security.
Technical summary
The Froxlor server administration software has a vulnerability in its API commands for customers, admins, and FTP users. An authenticated API caller can obtain full database rows, including password hashes and Base32-encoded TOTP seeds, which can be used to crack passwords offline and generate valid second-factor codes. The vulnerability exists in lib/Froxlor/Api/Commands/Customers.php, lib/Froxlor/Api/Commands/Admins.php, and lib/Froxlor/Api/Commands/Ftps.php. This issue is fixed in version 2.3.8. To mitigate, review and restrict API permissions, implement additional monitoring, update to version 2.3.8 or later, rotate passwords and TOTP seeds for affected accounts, and enable two-factor authentication for all accounts.
Defensive priority
Authenticated API callers with permission can exploit this vulnerability to obtain sensitive information, including password hashes and TOTP seeds, which can lead to account takeover.
Recommended defensive actions
- Review and restrict API permissions to limit exposure
- Implement additional monitoring for API usage
- Update to version 2.3.8 or later
- Rotate passwords and TOTP seeds for affected accounts
- Enable two-factor authentication for all accounts
Evidence notes
The CVE record and NVD entry provide details about the vulnerability in Froxlor server administration software. The vulnerability exists in API commands for retrieving customer, administrator, and FTP information without removing sensitive fields.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-62988 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-62988
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-62988 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-62988
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/froxlor/froxlor/commit/52a43fb826bb9a058faf9c39feeef7ac4444ceba
-
Source reference
Unverified legacy reference
URL: https://github.com/froxlor/froxlor/commit/8667fa3a4d77d6e322b7b8f7b9edbc1613ab5797
-
Source reference
Unverified legacy reference
URL: https://github.com/froxlor/froxlor/releases/tag/2.3.8
-
Source reference
Unverified legacy reference
URL: https://github.com/froxlor/froxlor/security/advisories/GHSA-7788-ghfq-c6mh
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.