THREAT OPS › Threat News › [GHSA] GHSA-7788-ghfq-c6mh (critical) — Froxlor: Credential and 2FA secret disclosure via Froxlor API endpoints
[GHSA] GHSA-7788-ghfq-c6mh (critical) — Froxlor: Credential and 2FA secret disclosure via Froxlor API endpoints
GHSA-7788-ghfq-c6mh Severity: critical CVE: CVE-2026-62988
Froxlor: Credential and 2FA secret disclosure via Froxlor API endpoints
## Summary
Several Froxlor API command classes return sensitive authentication material in JSON API responses. The affected endpoints retrieve full database rows using `SELECT *`, `SELECT alias.*`, or equivalent full-row queries, then return the results directly thr
MITRE ATT&CK techniques
- Private KeysT1552.004
Indicators of compromise
- CVE-2026-62988cve
Original source: https://github.com/advisories/GHSA-7788-ghfq-c6mh