CVE-2026-62988: Froxlor: API leaks password hashes & TOTP seeds

GHSA-7788-ghfq-c6mh CRITICAL PoC AVAILABLE CISA: ATTEND
Published August 18, 2026
CISO Take

Froxlor's admin API — specifically the Customers.get, Customers.listing, Admins.get, Admins.listing, Ftps.get, and Ftps.listing commands — returns full database rows including the password hash and data_2fa (TOTP seed) fields that should have been stripped before the response left the server. This matters because it lets an authenticated caller with legitimate permission to those endpoints harvest both authentication factors in one shot: password hashes can be cracked offline while the exposure is unaddressed, and the Base32 TOTP seed can generate valid second-factor codes indefinitely until 2FA is reset, together enabling full takeover of admin, customer, or FTP accounts. The bar for exploitation is not zero — CVSS PR:H means the attacker needs an already-authenticated account with API access to these commands, and there is no public exploit, Nuclei template, EPSS score, or CISA KEV listing to suggest active or automated exploitation at this time. Still, the CVSS 3.1 score of 9.0 (critical) reflects real severity if that bar is cleared — a compromised reseller, a malicious or careless staff account, or a leaked API token is enough. Patch to Froxlor 2.3.8 immediately, and treat any account that had API access to these endpoints before patching as potentially compromised: rotate its password and reset its 2FA seed rather than assuming the exposure window was benign.

Sources: NVD CISA KEV GitHub Advisory OpenSSF

What is the risk?

Rated critical (CVSS 3.1 9.0, AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L). The privileges-required (PR:H) constraint is the key mitigating factor: this is not remotely exploitable by an anonymous attacker, it requires an authenticated account already granted permission to the affected API commands, which meaningfully lowers the population of viable attackers to insiders, compromised reseller/staff accounts, or holders of leaked API credentials. There is no evidence of active exploitation (not in CISA KEV, no EPSS score available, no public PoC, no Nuclei template), and the package's own risk score (26/100) is comparatively low, consistent with a vulnerability that needs a privileged foothold rather than being opportunistically wormable. However, once that foothold exists, impact is severe and comprehensive: scope is changed (S:C), confidentiality and integrity impact are both high, and the compromise of both authentication factors (password + TOTP) simultaneously defeats defense-in-depth that 2FA is normally relied upon to provide. OpenSSF Scorecard of 6.8/10 and 59 other historical CVEs in this codebase suggest a moderately mature but not exceptionally hardened project.

How does the attack unfold?

Authenticated API Access
Attacker holds or compromises an account with legitimate API permission to call Customers.get/listing, Admins.get/listing, or Ftps.get/listing.
Bulk Credential Harvest
Attacker invokes the vulnerable endpoints, which return full database rows including the password hash and Base32 TOTP seed instead of redacting them.
Offline Cracking & TOTP Derivation
Attacker cracks harvested password hashes offline and generates valid time-based codes from the exposed TOTP seed, defeating both authentication factors.
Account Takeover
Attacker authenticates as the targeted admin, customer, or FTP account, gaining control of the hosting panel and hosted resources until credentials and 2FA are reset.

What systems are affected?

Package Ecosystem Vulnerable Range Patched
Panel composer < 2.3.8 2.3.8
5.8K OpenSSF 6.8 505 dependents Pushed 6d ago 68% patched ~15d to patch Full package profile →

Do you use Panel? You're affected.

How severe is it?

CVSS 3.1
9.0 / 10
EPSS
0.6%
chance of exploitation in 30 days
Higher than 48% of all CVEs
Exploitation Status
Exploit Available
Exploitation: MEDIUM
Sophistication
Trivial
Exploitation Confidence
medium
○ CISA SSVC: Public PoC
○ Public PoC indexed (trickest/cve)
Composite signal derived from CISA KEV, VulnCheck KEV, CISA SSVC, EPSS, Metasploit, Exploit-DB, trickest/cve, Nuclei templates, and inthewild.io exploitation reports.

What is the attack surface?

AV AC PR UI S C I A
AV Network
AC Low
PR High
UI None
S Changed
C High
I High
A Low

What should I do?

1 step
  1. Upgrade to Froxlor 2.3.8 immediately — the fix removes password and data_2fa fields from Customers/Admins/Ftps API responses (see the linked GitHub commits). Interim/compensating controls before patching: audit which API tokens or account roles currently hold permission to call Customers.get/listing, Admins.get/listing, and Ftps.get/listing, and revoke/tighten any that don't strictly need it. Treat the exposure as already-occurred for any account with that access prior to patching: rotate its password and reset its TOTP secret (re-enroll 2FA) rather than assuming no one abused the window. Detection: review Froxlor API access logs for calls to the six affected commands, particularly from reseller/customer-scoped credentials targeting Admins.get or other customers' Ftps.get — that pattern indicates likely abuse rather than legitimate self-service use.

What does CISA's SSVC say?

Decision Attend
Exploitation poc
Automatable No
Technical Impact total

Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.

How is it classified?

Data Leakage Auth Bypass API

Which compliance frameworks are affected?

Compliance analysis pending. Sign in for full compliance mapping when available.

Frequently Asked Questions

What is CVE-2026-62988?

Froxlor's admin API — specifically the Customers.get, Customers.listing, Admins.get, Admins.listing, Ftps.get, and Ftps.listing commands — returns full database rows including the password hash and data_2fa (TOTP seed) fields that should have been stripped before the response left the server. This matters because it lets an authenticated caller with legitimate permission to those endpoints harvest both authentication factors in one shot: password hashes can be cracked offline while the exposure is unaddressed, and the Base32 TOTP seed can generate valid second-factor codes indefinitely until 2FA is reset, together enabling full takeover of admin, customer, or FTP accounts. The bar for exploitation is not zero — CVSS PR:H means the attacker needs an already-authenticated account with API access to these commands, and there is no public exploit, Nuclei template, EPSS score, or CISA KEV listing to suggest active or automated exploitation at this time. Still, the CVSS 3.1 score of 9.0 (critical) reflects real severity if that bar is cleared — a compromised reseller, a malicious or careless staff account, or a leaked API token is enough. Patch to Froxlor 2.3.8 immediately, and treat any account that had API access to these endpoints before patching as potentially compromised: rotate its password and reset its 2FA seed rather than assuming the exposure window was benign.

Is CVE-2026-62988 actively exploited?

Proof-of-concept exploit code is publicly available for CVE-2026-62988, increasing the risk of exploitation.

How to fix CVE-2026-62988?

Upgrade to Froxlor 2.3.8 immediately — the fix removes password and data_2fa fields from Customers/Admins/Ftps API responses (see the linked GitHub commits). Interim/compensating controls before patching: audit which API tokens or account roles currently hold permission to call Customers.get/listing, Admins.get/listing, and Ftps.get/listing, and revoke/tighten any that don't strictly need it. Treat the exposure as already-occurred for any account with that access prior to patching: rotate its password and reset its TOTP secret (re-enroll 2FA) rather than assuming no one abused the window. Detection: review Froxlor API access logs for calls to the six affected commands, particularly from reseller/customer-scoped credentials targeting Admins.get or other customers' Ftps.get — that pattern indicates likely abuse rather than legitimate self-service use.

What is the CVSS score for CVE-2026-62988?

CVE-2026-62988 has a CVSS v3.1 base score of 9.0 (CRITICAL). The EPSS exploitation probability is 0.63%.

What are the technical details?

Original Advisory

Froxlor is open source server administration software. From 2.3.7 until 2.3.8, the Customers.get, Customers.listing, Admins.get, Admins.listing, Ftps.get, and Ftps.listing API commands in lib/Froxlor/Api/Commands/Customers.php, lib/Froxlor/Api/Commands/Admins.php, and lib/Froxlor/Api/Commands/Ftps.php retrieve full database rows and return them without removing password and data_2fa fields. An authenticated API caller with permission to use these endpoints can obtain customer, administrator, and FTP password hashes as well as Base32-encoded TOTP seeds for administrator and customer accounts. Password hashes can be cracked offline, and TOTP seeds can generate valid second-factor codes until two-factor authentication is reset. Exposure of both values for an account can enable takeover of the hosting panel or hosted resources and can defeat both authentication factors. This issue is fixed in version 2.3.8.

Exploitation Scenario

A malicious or compromised reseller account — which legitimately has API access to manage its own customers — calls Customers.listing and Ftps.listing against the vulnerable Froxlor instance. Instead of returning only account metadata, the API includes the raw password hash and Base32 TOTP seed for every customer and FTP account in scope, and if the account's permissions extend far enough, for admin accounts too. The attacker runs the hashes through an offline cracking tool (e.g., hashcat) while separately feeding the TOTP seed into a standard authenticator generator to produce valid 6-digit codes on demand. With both factors in hand, the attacker logs into the Froxlor panel as the compromised customer or admin, gaining control of hosted domains, DNS records, FTP file access, and downstream services managed through that panel — persisting until an administrator notices and forces a password/2FA reset.

Weaknesses (CWE)

CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor: The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

  • [Architecture and Design] Compartmentalize the system to have "safe" areas where trust boundaries can be unambiguously drawn. Do not allow sensitive data to go outside of the trust boundary and always be careful when interfacing with a compartment outside of the safe area. Ensure that appropriate compartmentalization is built into the system design, and the compartmentalization allows for and reinforces privilege separation functionality. Architects and designers should rely on the principle of least privilege to decide the appropriate time to use privileges and the time to drop privileges.

Source: MITRE CWE corpus.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L

Timeline

Published
August 18, 2026
Last Modified
August 21, 2026
First Seen
August 18, 2026

Related Vulnerabilities