CVE-2026-41235 - Froxlor has an authorization bypass in FTP shell assignment via missing server-side `available_shells` enforcement
CVE ID :CVE-2026-41235 Published : June 4, 2026, 7:16 p.m. | 1 hour, 57 minutes ago Description :Froxlor is open source server administration software. Version 2.3.6 lets administrators configure `system.available_shells` as the approved shell list that customers may assign to FTP users....