Froxlor before 2.3.7 fails to validate the mysql_server parameter against a customer's allowed_mysqlserver allowlist in the Mysqls.add API command. Attackers can supply a disallowed server index to create MySQL databases and users on forbidden servers, bypassing per-customer access controls.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-14 13:19
Updated : 2026-09-14 15:17
NVD link : CVE-2026-90935
Mitre link : CVE-2026-90935
CVE.ORG link : CVE-2026-90935
JSON object : View
Products Affected
No product.
CWE
CWE-285
Improper Authorization
