BlackTree Security · Infrastructure · Automation · AI

Froxlor’s Cleanup Job Could Erase Another Tenant’s Files

Deleting an FTP account can hand work to a privileged background job. Froxlor’s 6 September advisory describes how a customer-controlled symlink can redirect that later cleanup towards another directory. This is a consequential missed disclosure, revalidated after September indexing.

The record for CVE-2026-100715 concerns arbitrary directory deletion. The vendor advisory lists releases through 2.3.10 as affected and 2.3.12 as patched. It requires customer access and permission to write in the relevant FTP home.

The queued path can change before root uses it

Froxlor’s reproduction places the symlink after the FTP-deletion task is queued. The root cron worker applies string checks without establishing filesystem containment at execution time. The result can be deletion beyond the customer’s directory. This is not evidence of an unauthenticated takeover or an observed campaign.

Treat deletion as a shared-service risk

For a hosting operator, the important question is how much authority one cleanup worker holds. Map which customer requests become privileged background tasks and which storage each task can reach. Include retention jobs and account offboarding in that review, not just software installation.

A backup is useful only if the same administrative path cannot erase it. Test recovery of one tenant separately from whole-server recovery. Record how long each takes and who can authorise it, so the response is driven by evidence rather than the urgency of the first outage report.

What hosting operators should do

  • Upgrade to Froxlor 2.3.12 or later. The vendor release provides the fixed-version target.
  • Prioritise shared hosts. The business impact rises where multiple customers share one operating system and privileged cron service.
  • Inspect queued and recent FTP deletions. Correlate account-deletion events with cron logs, filesystem changes and service failures.
  • Review symlinks in customer homes. Unexpected links targeting paths outside the assigned home deserve investigation, especially around deletion times.
  • Protect backups from the same trust boundary. Ensure a customer account and the hosting panel’s privileged tasks cannot delete or rewrite recovery copies.
  • Use operating-system containment. Mount namespaces, separate storage and least-privileged helpers can reduce what a panel defect allows a root-labelled workflow to reach.

Use a benign test tenant for regression checks. The acceptance criterion is that legitimate cleanup succeeds while the worker cannot reach storage assigned to another tenant. Do not test with real customer data or a destructive production path.

The advisory includes reproduction details but does not report malicious exploitation. BlackTree’s earlier cPanel report covers a different mechanism with a related lesson about customer input reaching privileged hosting automation.

Sources

  • Froxlor security advisory, published 6 September 2026 at 09:59:39 UTC, 11:59:39 CEST. The public page exposed no separate update time.
  • Froxlor 2.3.12 release, published 23 August 2026 at 12:39:28 UTC, 14:39:28 CEST.
  • NVD record, published 26 September 2026 at 14:16:57 UTC, 16:16:57 CEST. The newly indexed record fell just before the previous cycle’s cutoff and was revalidated as a consequential missed item.

Leave a Reply

Your email address will not be published. Required fields are marked *