Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-41228

33
FAUCET Score

OVERVIEW CVE-2026-41228 affects Froxlor, an open-source server administration platform, in versions prior to 2.3.6. The vulnerability exists in the API endpoints for customer and administrator account updates, specifically in the "def_language" parameter which lacks proper validation against legitimate language files. This insufficient input validation enables authenticated users to inject path traversal sequences that ultimately lead to arbitrary code execution on the affected server. SEVERITY This is a critical vulnerability with a CVSS score of 9.9, indicating severe impact potential. The attack requires network access and low-privilege authentication (authenticated customer account) but no user interaction, making it highly exploitable once an attacker gains basic system access. The vulnerability allows complete compromise of system confidentiality, integrity, and availability, as malicious PHP code executes with web server privileges, potentially enabling full server takeover. EXPLOITATION STATUS The vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities catalog, suggesting no widespread active exploitation at this time. The EPSS score of 0.00055 indicates relatively low real-world exploitation probability compared to other published vulnerabilities. However, the technical simplicity of the exploit and moderate community attention warrant prompt patching, particularly for internet-facing Froxlor installations. Organizations should update to version 2.3.6 or later to remediate this risk.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.3.6CPE matchmatch criteria
cpe:2.3:a:froxlor:froxlor:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.9CRITICAL

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.1
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.52%
Probability of exploitation in next 30 days
EPSS Percentile
41.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0052 is in the 43rd percentile among its peer group of 1,124 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

composerpatch availablevia ghsa
Product: froxlor/froxlorFixed in: 2.3.6
github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

composerGHSA-w59f-67xm-rxx7critical

Froxlor has Local File Inclusion via path traversal in API `def_language` parameter leads to Remote Code Execution

Apr 16, 2026

References

github.com / froxlor/froxlor/commit/bc5e6dbaa90e6f3573129da640595e8c770e1d0c
Patch
github.com / froxlor/froxlor/releases/tag/2.3.6
Release Notes
github.com / froxlor/froxlor/security/advisories/GHSA-w59f-67xm-rxx7
ExploitMitigationVendor Advisory