PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-90767 froxlor CVE debrief

CVE-2026-90767 is a vulnerability in Froxlor versions before 2.3.12 that allows customers to inject arbitrary lines into authorized_keys files via the SshKeys::add() endpoint. This enables attackers to gain persistent unauthorized access. The vulnerability affects Froxlor installations, and defenders should assess exposure and apply remediation. The issue arises from improper validation of multi-line SSH public keys, allowing malicious SSH key entries with option directives. Verification of Froxlor versions and SSH key configurations is necessary to prevent unauthorized access.

Vendor
froxlor
Product
Unknown
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-13
Original CVE updated
2026-09-23
Advisory published
2026-09-13
Advisory updated
2026-09-23

Who should care

Defenders responsible for Froxlor installations, SSH key management, and access control should assess exposure and apply remediation. This includes verifying Froxlor versions, reviewing SSH key configurations, and ensuring that compensating controls are in place for exposed systems. The vulnerability's impact on security teams and vulnerability management processes necessitates prompt attention and remediation to prevent unauthorized access and potential

Why it matters

CVE-2026-90767 allows attackers to inject arbitrary lines into authorized_keys files, enabling persistent unauthorized access. Defenders should verify Froxlor installations, review SSH key configurations, and apply remediation to prevent unauthorized access.

  • Persistent unauthorized access can survive key deletion and SSH access revocation.
  • Attackers can inject malicious SSH key entries with option directives.
  • Verification of Froxlor versions and SSH key configurations is necessary.
  • Remediation priority is high due to the potential for unauthorized access.

Technical summary

Froxlor versions before 2.3.12 are vulnerable to SSH key injection via the SshKeys::add() endpoint. This allows attackers to inject malicious SSH key entries with option directives, enabling persistent unauthorized access. The vulnerability arises from improper validation of multi-line SSH public keys. Defenders should prioritize verifying Froxlor installations for exposure, reviewing SSH key configurations, and applying the vendor's remediation to prevent unauthorized access and potential operational impacts associated with the vulnerability.

Defensive priority

Defenders should prioritize verifying Froxlor installations for exposure, reviewing SSH key configurations, and applying the vendor's remediation.

Recommended defensive actions

  • Verify Froxlor installations for exposure by checking the version and reviewing SSH key configurations.
  • Apply the vendor's remediation by updating to Froxlor version 2.3.12 or later.
  • Review and restrict SSH access and key management practices to prevent unauthorized access.
  • Track exceptions and retest remediated assets.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability. However, the scope of affected versions and deployments requires verification. Defenders should verify Froxlor installations for exposure by checking the version and reviewing SSH key configurations. The vulnerability allows attackers to inject malicious SSH key entries with option directives, enabling persistent unauthorized access that survives key deletion and SSH access revocation.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-90767 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-90767

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-90767 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-90767

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.