OVERVIEW CVE-2026-41228 affects Froxlor, an open-source server administration platform, in versions prior to 2.3.6. The vulnerability exists in the API endpoints for customer and administrator account updates, specifically in the "def_language" parameter which lacks proper validation against legitimate language files. This insufficient input validation enables authenticated users to inject path traversal sequences that ultimately lead to arbitrary code execution on the affected server. SEVERITY This is a critical vulnerability with a CVSS score of 9.9, indicating severe impact potential. The attack requires network access and low-privilege authentication (authenticated customer account) but no user interaction, making it highly exploitable once an attacker gains basic system access. The vulnerability allows complete compromise of system confidentiality, integrity, and availability, as malicious PHP code executes with web server privileges, potentially enabling full server takeover. EXPLOITATION STATUS The vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities catalog, suggesting no widespread active exploitation at this time. The EPSS score of 0.00055 indicates relatively low real-world exploitation probability compared to other published vulnerabilities. However, the technical simplicity of the exploit and moderate community attention warrant prompt patching, particularly for internet-facing Froxlor installations. Organizations should update to version 2.3.6 or later to remediate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.3.6CPE matchmatch criteria | cpe:2.3:a:froxlor:froxlor:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.