What is CVE-2026-54348?
CVE-2026-54348 is a security vulnerability in Froxlor server administration software. In versions prior to 2.3.8, the Admins.add and Admins.update endpoints fail to enforce numeric element types for the ipaddress array, allowing an attacker to inject malicious data into stored JSON. Users should immediately upgrade to version 2.3.8 or later.
Azərbaycanca: CVE-2026-54348 Froxlor server idarəetmə proqramında aşkarlanmış təhlükəsizlik zəifliyidir. 2.3.8 versiyasından əvvəlki versiyalarda, `Admins.add` və `Admins.update` endpointləri `ipaddress` parametrini düzgün yoxlamadığı üçün təcavüzkar JSON məlumatına zərərli məlumat daxil edə bilər. İstifadəçilər dərhal 2.3.8 və ya daha yeni versiyaya yeniləməlidir.
FAQ2
Which versions of Froxlor are affected by CVE-2026-54348?
This vulnerability affects all versions of Froxlor prior to 2.3.8.
What is the root cause of the CVE-2026-54348 vulnerability?
The vulnerability stems from the Admins.add and Admins.update endpoints failing to enforce numeric element types for the ipaddress array.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.