Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 14 Sep 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 13 Sep 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing customers to inject arbitrary lines into authorized_keys files. Attackers can inject malicious SSH key entries with option directives to gain persistent unauthorized access that survives key deletion and SSH access revocation. | |
| Title | Froxlor before 2.3.12 SSH Key Injection via authorized_keys | |
| First Time appeared |
Froxlor
Froxlor froxlor |
|
| Weaknesses | CWE-93 | |
| CPEs | cpe:2.3:a:froxlor:froxlor:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Froxlor
Froxlor froxlor |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-14T17:42:31.715Z
Reserved: 2026-09-13T10:14:51.758Z
Link: CVE-2026-90767
Updated: 2026-09-14T17:42:26.332Z
Status : Received
Published: 2026-09-13T11:17:00.947
Modified: 2026-09-14T18:20:25.200
Link: CVE-2026-90767
No data.
OpenCVE Enrichment
Updated: 2026-09-15T17:15:14Z