# CVE-2026-90767

## Summary

- **CVE ID:** CVE-2026-90767
- **Severity:** HIGH
- **CVSS Score:** 7.1 (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-93
- **Published:** Sep 13, 2026
- **Last Modified:** Sep 14, 2026

## Description

Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing customers to inject arbitrary lines into authorized_keys files. Attackers can inject malicious SSH key entries with option directives to gain persistent unauthorized access that survives key deletion and SSH access revocation.

## Affected Products

- froxlor — Froxlor (0)

## References

- [CNA](https://github.com/froxlor/Froxlor/security/advisories/GHSA-p3v3-74gc-jh5f)
- [CNA](https://github.com/froxlor/Froxlor/blob/2.3.10/lib/Froxlor/Api/Commands/SshKeys.php)
- [CNA](https://github.com/froxlor/Froxlor/blob/2.3.10/lib/Froxlor/Cron/System/SshKeys.php)
- [CNA](https://github.com/froxlor/Froxlor)
- [CNA](https://www.vulncheck.com/advisories/froxlor-before-2.3.12-ssh-key-injection-via-authorized-keys)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.25%
- **EPSS Percentile:** 16.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-19._