CVE-2026-90767
Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing customers to inject arbitrary lines into authorized_keys files. Attackers can inject malicious SSH key entries with option directives to gain persistent unauthorized access that survives key deletion and SSH access revocation.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.1
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.25%
- CWE
- CWE-93
- Published
- 2026-09-13
- Last modified
- 2026-09-14
Affected products
- froxlor Froxlor
Weakness type
Related vulnerabilities
- CVE-2021-39172 — New line injection during configuration edition
- CVE-2024-51501 — CRLF injection in Refit's [Header], [HeaderCollection] and [Authorize] attributes
- CVE-2024-32986 — Arbitrary code execution due to improper sanitization of web app properties in PWAsForFirefox
- CVE-2025-40671 — SQL injection vulnerability in AES Multimedia's Gestnet
- CVE-2026-29046 — TinyWeb: HTTP Header Control Character Injection into CGI Environment
- CVE-2025-8715 — PostgreSQL pg_dump newline in object name executes arbitrary code in psql client and in restore target server
- CVE-2022-0666 — CRLF Injection leads to Stack Trace Exposure due to lack of filtering at https://demo.microweber.org/ in microweber/microweber
- CVE-2026-23953 — Incus container environment configuration newline injection