
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-30932 is a BIND zone file injection vulnerability in Froxlor, an open-source server control panel, caused by unsanitized DNS record content in the DomainZones API. The vulnerability affects all Froxlor versions up to and including 2.3.4, and was disclosed on March 24, 2026 via a GitHub Security Advisory. It carries a CVSS v3.1 base score of 8.8 (High) and a CVSS v4.0 base score of 8.6 (High) (Github Advisory, Feedly).
The root cause is CWE-74 (Improper Neutralization of Special Elements in Output Used by a Downstream Component — Injection). The DomainZones.add API endpoint in lib/Froxlor/Api/Commands/DomainZones.php performs no input validation on the content field for DNS record types LOC, RP, SSHFP, and TLSA — the source code even contains a // no validation comment and an unresolved // TODO regex validate content for invalid characters note. An authenticated customer with DNS management privileges can inject newline characters and BIND zone file directives (e.g., $INCLUDE, $GENERATE) into the content field; this content is written verbatim into the BIND zone file on disk via DnsEntry::__toString() and fwrite() in lib/Froxlor/Cron/Dns/Bind.php when the DNS rebuild cron job executes (Github Advisory, Froxlor Commit).
Successful exploitation enables three distinct attack scenarios: (1) Information Disclosure — injecting $INCLUDE /etc/passwd causes BIND to read world-readable server files, with the zone content (including included file data) exposed to the attacker via the DomainZones.get API or the web UI DNS editor; (2) DNS Service Disruption — malformed zone content causes BIND to fail loading the zone, resulting in DNS outages for the affected domain, and injected $GENERATE directives can create massive record sets usable for amplification attacks; (3) Zone Data Manipulation — arbitrary DNS records can be injected via newline characters, allowing creation of records outside the attacker's intended scope (Github Advisory, Feedly).
A proof-of-concept exploit is publicly available in the GitHub Security Advisory, consisting of a concrete curl command targeting the DomainZones.add API endpoint with a crafted JSON payload containing injected BIND directives. Exploitation requires only low-privilege authenticated access (a customer API key with DNS management enabled), and no user interaction or special conditions are needed beyond waiting for the DNS rebuild cron job to execute. The EPSS score is approximately 0.025% (0.044% per Feedly), and there is no evidence of in-the-wild exploitation or CISA KEV catalog listing at this time (Github Advisory, Feedly).
example.com).DomainZones.add command with a LOC record type whose content field embeds a newline followed by a BIND directive, e.g., "content": "0 0 0 N 0 0 0 E 0\n$INCLUDE /etc/passwd".curl -s -u "API_KEY:API_SECRET" \
-H 'Content-Type: application/json' \
-d '{"command":"DomainZones.add","params":{"domainname":"example.com","type":"LOC","content":"0 0 0 N 0 0 0 E 0\n$INCLUDE /etc/passwd"}}' \
https://panel.example.com/api.phpAlternatively, intercept the DNS editor web UI form POST and modify the dns_content and dns_type fields directly.
4. Wait for cron execution: The DNS rebuild cron job writes the injected content into the BIND zone file at {bindconf_directory}/domains/example.com.zone, resulting in a zone file containing the raw $INCLUDE /etc/passwd directive.
5. Retrieve disclosed data: Call DomainZones.get via the API or view the DNS editor in the web UI to read the zone content, including any parseable lines from the included server file (Github Advisory).
/api.php with DomainZones.add commands containing LOC, RP, SSHFP, or TLSA record types with abnormally long or multi-line content fields; subsequent DomainZones.get calls from the same account shortly after a cron execution.{bindconf_directory}/domains/ containing unexpected directives such as $INCLUDE, $GENERATE, or embedded newlines within record content fields; zone files referencing sensitive paths like /etc/passwd, /etc/shadow, or SSH key files.DomainZones.add API calls with suspicious content parameters; BIND/named logs (/var/log/named/ or syslog) showing zone load failures, parse errors for unexpected file paths, or warnings about $INCLUDE directives referencing non-zone files.named/bind process attempting to open files outside the standard zone directory (e.g., /etc/passwd) as detected by auditd or strace (Github Advisory).Upgrade Froxlor to version 2.3.5 or later, which adds strict format validation for LOC, RP, SSHFP, and TLSA record content via new Validate::validateDnsLoc(), validateDnsRp(), validateDnsSshfp(), and validateDnsTlsa() methods in lib/Froxlor/Validate/Validate.php (Froxlor Release, Froxlor Commit). As a short-term workaround where immediate upgrade is not possible, restrict DNS zone management permissions to trusted administrators only and monitor zone files and API logs for suspicious content. Consider configuring BIND's named.conf to restrict the directories accessible via $INCLUDE directives using the directory option.
The vulnerability was reported by researcher q1uf3ng and published by Froxlor maintainer d00p (Michael Kaufmann) on March 24, 2026. The advisory was noted in the CISA weekly vulnerability bulletin for the week of June 1, 2026, indicating broader awareness in the security community (CISA Bulletin). No significant independent researcher commentary or social media discussion has been identified beyond standard vulnerability database aggregation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."