CVE-2026-30932: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-30932 is a BIND zone file injection vulnerability in Froxlor, an open-source server control panel, caused by unsanitized DNS record content in the DomainZones API. The vulnerability affects all Froxlor versions up to and including 2.3.4, and was disclosed on March 24, 2026 via a GitHub Security Advisory. It carries a CVSS v3.1 base score of 8.8 (High) and a CVSS v4.0 base score of 8.6 (High) (Github Advisory, Feedly).

Technical details

The root cause is CWE-74 (Improper Neutralization of Special Elements in Output Used by a Downstream Component — Injection). The DomainZones.add API endpoint in lib/Froxlor/Api/Commands/DomainZones.php performs no input validation on the content field for DNS record types LOC, RP, SSHFP, and TLSA — the source code even contains a // no validation comment and an unresolved // TODO regex validate content for invalid characters note. An authenticated customer with DNS management privileges can inject newline characters and BIND zone file directives (e.g., $INCLUDE, $GENERATE) into the content field; this content is written verbatim into the BIND zone file on disk via DnsEntry::__toString() and fwrite() in lib/Froxlor/Cron/Dns/Bind.php when the DNS rebuild cron job executes (Github Advisory, Froxlor Commit).

Impact

Successful exploitation enables three distinct attack scenarios: (1) Information Disclosure — injecting $INCLUDE /etc/passwd causes BIND to read world-readable server files, with the zone content (including included file data) exposed to the attacker via the DomainZones.get API or the web UI DNS editor; (2) DNS Service Disruption — malformed zone content causes BIND to fail loading the zone, resulting in DNS outages for the affected domain, and injected $GENERATE directives can create massive record sets usable for amplification attacks; (3) Zone Data Manipulation — arbitrary DNS records can be injected via newline characters, allowing creation of records outside the attacker's intended scope (Github Advisory, Feedly).

Exploitability

A proof-of-concept exploit is publicly available in the GitHub Security Advisory, consisting of a concrete curl command targeting the DomainZones.add API endpoint with a crafted JSON payload containing injected BIND directives. Exploitation requires only low-privilege authenticated access (a customer API key with DNS management enabled), and no user interaction or special conditions are needed beyond waiting for the DNS rebuild cron job to execute. The EPSS score is approximately 0.025% (0.044% per Feedly), and there is no evidence of in-the-wild exploitation or CISA KEV catalog listing at this time (Github Advisory, Feedly).

Exploitation steps

  1. Obtain credentials: Acquire a Froxlor customer account API key and secret with DNS zone management permissions enabled for a domain (e.g., example.com).
  2. Craft the malicious payload: Construct a JSON payload targeting the DomainZones.add command with a LOC record type whose content field embeds a newline followed by a BIND directive, e.g., "content": "0 0 0 N 0 0 0 E 0\n$INCLUDE /etc/passwd".
  3. Submit via API: Send the crafted request to the Froxlor API endpoint:
curl -s -u "API_KEY:API_SECRET" \
  -H 'Content-Type: application/json' \
  -d '{"command":"DomainZones.add","params":{"domainname":"example.com","type":"LOC","content":"0 0 0 N 0 0 0 E 0\n$INCLUDE /etc/passwd"}}' \
  https://panel.example.com/api.php

Alternatively, intercept the DNS editor web UI form POST and modify the dns_content and dns_type fields directly. 4. Wait for cron execution: The DNS rebuild cron job writes the injected content into the BIND zone file at {bindconf_directory}/domains/example.com.zone, resulting in a zone file containing the raw $INCLUDE /etc/passwd directive. 5. Retrieve disclosed data: Call DomainZones.get via the API or view the DNS editor in the web UI to read the zone content, including any parseable lines from the included server file (Github Advisory).

Indicators of compromise

  • Network: Unusual API calls to /api.php with DomainZones.add commands containing LOC, RP, SSHFP, or TLSA record types with abnormally long or multi-line content fields; subsequent DomainZones.get calls from the same account shortly after a cron execution.
  • File System: BIND zone files in {bindconf_directory}/domains/ containing unexpected directives such as $INCLUDE, $GENERATE, or embedded newlines within record content fields; zone files referencing sensitive paths like /etc/passwd, /etc/shadow, or SSH key files.
  • Logs: Froxlor application logs showing DomainZones.add API calls with suspicious content parameters; BIND/named logs (/var/log/named/ or syslog) showing zone load failures, parse errors for unexpected file paths, or warnings about $INCLUDE directives referencing non-zone files.
  • Process: The named/bind process attempting to open files outside the standard zone directory (e.g., /etc/passwd) as detected by auditd or strace (Github Advisory).

Mitigation and workarounds

Upgrade Froxlor to version 2.3.5 or later, which adds strict format validation for LOC, RP, SSHFP, and TLSA record content via new Validate::validateDnsLoc(), validateDnsRp(), validateDnsSshfp(), and validateDnsTlsa() methods in lib/Froxlor/Validate/Validate.php (Froxlor Release, Froxlor Commit). As a short-term workaround where immediate upgrade is not possible, restrict DNS zone management permissions to trusted administrators only and monitor zone files and API logs for suspicious content. Consider configuring BIND's named.conf to restrict the directories accessible via $INCLUDE directives using the directory option.

Community reactions

The vulnerability was reported by researcher q1uf3ng and published by Froxlor maintainer d00p (Michael Kaufmann) on March 24, 2026. The advisory was noted in the CISA weekly vulnerability bulletin for the week of June 1, 2026, indicating broader awareness in the security community (CISA Bulletin). No significant independent researcher commentary or social media discussion has been identified beyond standard vulnerability database aggregation.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management