Sploitus

CVE-2026-41235

No indexed exploits for CVE-2026-41235 yet

Froxlor is open source server administration software. Version 2.3.6 lets administrators configure `system.available_shells` as the approved shell list that customers may assign to FTP users. However, the server-side FTP account handlers do not enforce that whitelist when processing add or edit requests. As a result, an authenticated customer with shell delegation enabled can submit an arbitrary shell such as `/bin/bash` even when the panel UI only offers more restricted choices. In deployments that use the default `nssextrausers` integration, the attacker-controlled shell is then propagated into the system account database, leading to real host shell access. Version 2.3.7 fixes the issue.

Affected products
Froxlor
Fix
Available
CVSS 4.0
9.4 CRITICAL
EPSS
0.2% (14th percentile)
Weakness
CWE-863
NVD status
Deferred
Published
2026-06-04
CVE-2026-41235 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-41235 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-41235 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.