CVE-2026-100719
Deferred Deferred - Pending Action

Froxlor Credential Disclosure via DirProtections.listing API

Vulnerability report for CVE-2026-100719, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-26

Last updated on: 2026-09-26

Assigner: VulnCheck

Description

Froxlor versions before 2.3.12 contain a credential disclosure vulnerability in the DirProtections.listing API command that returns htpasswd password hashes. Authenticated API users can retrieve bcrypt password hashes for protected-directory users, enabling offline cracking attempts and exposure of reused credentials.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-26
Last Modified
2026-09-26
Generated
2026-09-26
AI Q&A
2026-09-26
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
froxlor froxlor to 2.3.12 (exc)
froxlor froxlor to 2.3.10 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Froxlor versions before 2.3.12 have a vulnerability in the DirProtections.listing API command that exposes bcrypt password hashes for users of protected directories. Authenticated API users can retrieve these hashes, which can then be used for offline cracking attempts.

Detection Guidance

To detect this vulnerability, check if your Froxlor version is below 2.3.12. Use the command 'froxlor --version' to verify. If vulnerable, inspect API responses for DirProtections.listing commands to see if bcrypt password hashes are exposed.

Impact Analysis

If you use Froxlor versions before 2.3.12, an attacker with API access could obtain bcrypt password hashes. If passwords are reused, this could lead to unauthorized access to other systems or accounts. The vulnerability allows for offline cracking attempts, increasing the risk of credential compromise.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection requirements and HIPAA's security rules for protected health information. Organizations may face compliance violations, legal penalties, and reputational damage if exploited.

Mitigation Strategies

Immediately upgrade Froxlor to version 2.3.12 or later. Revoke and regenerate all API keys to prevent unauthorized access. Review htpasswd files for exposed bcrypt hashes and force password resets for affected users.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-100719. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart