THREAT OPS › Threat News › [NVD] CVE-2026-90767 (MEDIUM 6.5) — Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing customers to inject arbitrary lines into authorized_keys files. Attackers can inject malicious SSH key entries with option directives to gain persistent unauthoriz
[NVD] CVE-2026-90767 (MEDIUM 6.5) — Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing customers to inject arbitrary lines into authorized_keys files. Attackers can inject malicious SSH key entries with option directives to gain persistent unauthoriz
CVE-2026-90767 CVSS: 6.5 MEDIUM Published: 2026-09-13T11:17:00.947
Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing customers to inject arbitrary lines into authorized_keys files. Attackers can inject malicious SSH key entries with option directives to gain persistent unauthorized access that survives key deletion and SSH access
Indicators of compromise
- CVE-2026-90767cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-90767