CVE-2026-30932 is a critical input validation vulnerability affecting Froxlor server administration software prior to version 2.3.5. An authenticated attacker with DNS enabled can exploit the DomainZones.add API endpoint to inject BIND zone file directives, such as $INCLUDE, into DNS zone files. This can lead to arbitrary file inclusion or execution when the DNS rebuild cron job runs, resulting in a high impact on confidentiality, integrity, and availability. The attack vector is network-based and requires low privileges, earning a CVSS score of 8.8 HIGH. Currently, there is no public exploit code, evidence of active exploitation, or significant community discussion reported for this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.3.5CPE matchmatch criteria | cpe:2.3:a:froxlor:froxlor:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.