What is CVE-2026-52793?
CVE-2026-52793 is a critical authentication bypass in Froxlor server management software. In versions prior to 2.3.7, the API authentication mechanism fails to enforce two-factor authentication (TOTP), allowing attackers with only an API key and secret to access administrator accounts. Users must immediately upgrade to version 2.3.7.
Azərbaycanca: CVE-2026-52793, Froxlor server idarəetmə proqramında aşkarlanan kritik autentifikasiya boşluğudur. 2.3.7 versiyasından əvvəlki versiyalarda API autentifikasiya mexanizmi iki faktorlu autentifikasiyanı (TOTP) yoxlamır, bu da təcavüzkarlara yalnız API açarı ilə administrator hesablarına giriş imkanı verir. Froxlor istifadəçiləri dərhal 2.3.7 versiyasına yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
What is CVE-2026-52793?
CVE-2026-52793 is a critical authentication bypass in Froxlor server management software.
Which Froxlor version should users upgrade to in order to protect against CVE-2026-52793?
Users must immediately upgrade to version 2.3.7.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.