<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 13:57:22 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-274211</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-274211</link>
      <description>EUVD-2026-274211</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-274211</guid>
    </item>
    <item>
      <title>fkie_cve-2026-26279</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-26279</link>
      <description>&lt;p&gt;Froxlor is open source server administration software. Prior to 2.3.4, a typo in Froxlor&amp;#39;s input validation code (== instead of =) completely disables email format checking for all settings fields declared as email type. This allows an authenticated admin to store arbitrary strings in the panel.adminmail setting. This value is later concatenated into a shell command executed as root by a cron job, where the pipe character | is explicitly whitelisted. The result is full root-level Remote Code Execution. This vulnerability is fixed in 2.3.4.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Froxlor is open source server administration software. Prior to 2.3.4, a typo in Froxlor&amp;#39;s input validation code (== instead of =) completely disables email format checking for all settings fields declared as email type. This allows an authenticated admin to store arbitrary strings in the panel.adminmail setting. This value is later concatenated into a shell command executed as root by a cron job, where the pipe character | is explicitly whitelisted. The result is full root-level Remote Code Execution. This vulnerability is fixed in 2.3.4.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-26279</guid>
    </item>
    <item>
      <title>GHSA-33mp-8p67-xj7c — Froxlor has Admin-to-Root Privilege Escalation via Input Validation Bypass + OS Command Injection</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-33mp-8p67-xj7c</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: froxlor/froxlor&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A typo in Froxlor&amp;#39;s input validation code (`==` instead of `=`) completely disables email format checking for all settings fields declared as email type. This allows an authenticated admin to store arbitrary strings — including shell metacharacters — in the `panel.adminmail` setting. This value is later concatenated into a shell command executed as **root** by a cron job, where the pipe character `|` is explicitly whitelisted. The result is **full root-level Remote Code Execution**.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Why This Is a Security Vulnerability (Not Just &amp;#34;Admin Using Admin Features&amp;#34;)&lt;/p&gt;
&lt;p&gt;Froxlor is a **shared hosting control panel**. In production deployments:&lt;/p&gt;
&lt;p&gt;1. **Admin panel access does not equal root access.** Hosting providers assign the Froxlor admin role to staff who manage customer accounts, domains, and services through the web UI. These operators are not given SSH access or root shell on the underlying server. The boundary between &amp;#34;panel admin&amp;#34; and &amp;#34;OS root&amp;#34; is a deliberate security design.&lt;/p&gt;
&lt;p&gt;2. **Froxlor itself enforces this boundary.** The `safe_exec()` function (FileDir.php:224-264) exists specifically to prevent shell injection — it blocks `;`, `|`, `&amp;amp;`, `&amp;gt;`, `&amp;lt;`, `` ` ``, `$`, `~`, `?`. The email validation function (`validateFormFieldEmail`) exists specifically to ensure email fields contain valid emails. Both mechanisms are security boundaries that this vulnerability bypasses.&lt;/p&gt;
&lt;p&gt;3. **The root cause is an unintentional code defect.** The `==` operator on a standalone l…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: froxlor/froxlor&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A typo in Froxlor&amp;#39;s input validation code (`==` instead of `=`) completely disables email format checking for all settings fields declared as email type. This allows an authenticated admin to store arbitrary strings — including shell metacharacters — in the `panel.adminmail` setting. This value is later concatenated into a shell command executed as **root** by a cron job, where the pipe character `|` is explicitly whitelisted. The result is **full root-level Remote Code Execution**.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Why This Is a Security Vulnerability (Not Just &amp;#34;Admin Using Admin Features&amp;#34;)&lt;/p&gt;
&lt;p&gt;Froxlor is a **shared hosting control panel**. In production deployments:&lt;/p&gt;
&lt;p&gt;1. **Admin panel access does not equal root access.** Hosting providers assign the Froxlor admin role to staff who manage customer accounts, domains, and services through the web UI. These operators are not given SSH access or root shell on the underlying server. The boundary between &amp;#34;panel admin&amp;#34; and &amp;#34;OS root&amp;#34; is a deliberate security design.&lt;/p&gt;
&lt;p&gt;2. **Froxlor itself enforces this boundary.** The `safe_exec()` function (FileDir.php:224-264) exists specifically to prevent shell injection — it blocks `;`, `|`, `&amp;amp;`, `&amp;gt;`, `&amp;lt;`, `` ` ``, `$`, `~`, `?`. The email validation function (`validateFormFieldEmail`) exists specifically to ensure email fields contain valid emails. Both mechanisms are security boundaries that this vulnerability bypasses.&lt;/p&gt;
&lt;p&gt;3. **The root cause is an unintentional code defect.** The `==` operator on a standalone l…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-33mp-8p67-xj7c</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0577 — Froxlor: Schwachstelle ermöglicht Privilegieneskalation</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0577</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Froxlor ausnutzen, um seine Privilegien zu erhöhen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Froxlor ausnutzen, um seine Privilegien zu erhöhen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0577</guid>
    </item>
  </channel>
</rss>
