CVE-2026-41228
Froxlor is open source server administration software. Prior to version 2.3.6, the Froxlor API endpoint Customers.update (and Admins.update) does not validate the def_language parameter against the list of available language files. An authenticated customer can set def_language to a path traversal payload (e.g., ../../../../../var/customers/webs/customer1/evil), which is stored in the database. On subsequent requests, Language::loadLanguage() constructs a file path using this value and executes it via require, achieving arbitrary PHP code execution as the web server user. Version 2.3.6 fixes the issue.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/froxlor/froxlor/releases/tag/2.3.6, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41228.json, https://github.com/froxlor/froxlor/security/advisories/GHSA-w59f-67xm-rxx7, https://nvd.nist.gov/vuln/detail/CVE-2026-41228, https://github.com/froxlor/froxlor/commit/bc5e6dbaa90e6f3573129da640595e8c770e1d0c