THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-90767 (MEDIUM 6.5) — Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing customers to inject arbitrary lines into authorized_keys files. Attackers can inject malicious SSH key entries with option directives to gain persistent unauthoriz

[NVD] CVE-2026-90767 (MEDIUM 6.5) — Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing customers to inject arbitrary lines into authorized_keys files. Attackers can inject malicious SSH key entries with option directives to gain persistent unauthoriz

mednvdPublished 2026-09-13

CVE-2026-90767 CVSS: 6.5 MEDIUM Published: 2026-09-13T11:17:00.947

Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing customers to inject arbitrary lines into authorized_keys files. Attackers can inject malicious SSH key entries with option directives to gain persistent unauthorized access that survives key deletion and SSH access

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-90767