Roxy-WI是Roxy-WI开源的一款用于管理 Haproxy、Nginx 和 Keepalived 服务器的 Web 界面。 Roxy-WI 8.2.6.4及之前版本存在安全漏洞,该漏洞源于GET /history/路由在service为user时未进行授权检查,可能导致任何认证用户列出其他用户的完整操作审计记录。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-45556 | 9.9 CRITICAL | Roxy-WI: Authenticated arbitrary file write on every managed load balancer (and downstream |
| CVE-2026-45558 | 9.9 CRITICAL | Roxy-WI: Authenticated RCE on every managed HAProxy load balancer via `option` field confi |
| CVE-2026-45552 | 9.9 CRITICAL | Roxy-WI: Cross-tenant authorization bypass on /install/* — guest can run Ansible / SSH on |
| CVE-2026-45550 | 9.1 CRITICAL | Roxy-WI: IDOR on PUT /smon/check — any user can rewrite any tenant's monitoring URL/IP/bod |
| CVE-2026-45564 | 8.8 HIGH | Roxy-WI: Authenticated RCE via 'configver' URL parameter (os.system sink in /config/versio |
| CVE-2026-45549 | 8.5 HIGH | Roxy-WI: Authorization bypass on POST /smon/agent/action/<action> — guest can stop or rest |
| CVE-2026-45567 | 8.3 HIGH | Roxy-WI: Authentication bypass via 'api' substring in URL + unauthenticated /api/gpt |
| CVE-2026-45569 | 8.1 HIGH | Roxy-WI: Path-traversal patch in commit d4d10006 is a no-op (tuple-membership bug) |
| CVE-2026-45565 | 8.1 HIGH | Roxy-WI: EscapedString validator skips its '..' block when stripping (root cause for sever |
| CVE-2026-45561 | 6.5 MEDIUM | Roxy-WI: SSRF in /smon/agent/<endpoint>/<server_ip> reachable to cloud metadata IPs |
| CVE-2026-45566 | 6.1 MEDIUM | Roxy-WI: Open redirect on /login?next= via basic-auth userinfo syntax bypass |
| CVE-2026-45560 | 6.1 MEDIUM | Roxy-WI: Stored XSS in log viewer (wrap_line/highlight_word produce unescaped HTML) |
| CVE-2026-45559 | 4.9 MEDIUM | Roxy-WI: LDAP injection in /user/ldap/<username> (admin-only) |
No comments yet