CRITICAL 9.6 CVE-2026-100715 Published 26 Sept 2026

Froxlor FTP Cron Symlink Arbitrary File Deletion Vulnerability

Worried this affects your website?

Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via symlink following in the FTP data deletion cron task.

Cron task 8 (deleteFtpData), queued when an FTP account is deleted, calls FileDir::makeCorrectDir() without the $fixed_homedir argument, so the symlink component walk is skipped, and then executes 'rm -rf' as root on the resulting path with string-level guards only. Because makeCorrectDir() appends a trailing slash, GNU rm dereferences a symlink used either as an intermediate path component or as the final component.

  • Affected versions: Froxlor through 2.3.10; fixed in 2.3.12.
  • Precondition: an authenticated customer who can write to the FTP home directory can plant a symlink between task insertion and cron execution.
  • Impact: the root cron job recursively deletes arbitrary directory trees, causing cross-tenant data destruction and host denial of service.

Reference: CVE-2026-100715 on NVD

← Back to Security News