Vulnerability Description
Froxlor before 2.3.7 fails to validate the mysql_server parameter against a customer's allowed_mysqlserver allowlist in the Mysqls.add API command. Attackers can supply a disallowed server index to create MySQL databases and users on forbidden servers, bypassing per-customer access controls.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/froxlor/froxlor/security/advisories/GHSA-q4rm-m6xh-5pv7
- https://www.vulncheck.com/advisories/froxlor-before-2.3.7-authorization-bypass-v
- https://github.com/froxlor/froxlor/security/advisories/GHSA-q4rm-m6xh-5pv7
FAQ
What is CVE-2026-90935?
CVE-2026-90935 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Froxlor before 2.3.7 fails to validate the mysql_server parameter against a customer's allowed_mysqlserver allowlist in the Mysqls.add API command. Attackers can supply a disallowed server index to cr...
How severe is CVE-2026-90935?
CVE-2026-90935 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-90935?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.