CVE 9.9 CRITICAL

Roxy-WI: Cross-tenant authorization bypass on /install/* — guest can run Ansible / SSH on every registered server_CVE-2026-45552

9.9 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Description

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the install blueprint declares only bp.before_request → @jwt_required() (app/routes/install/routes.py:36-39). The individual endpoints install_exporter, install_waf, install_geoip, check_geoip, get_exporter_version, and get_task_status are not wrapped in page_for_admin and do not call roxywi_common.is_user_has_access_to_its_group(server_ip) or check_is_server_in_group(server_ip). Only the GET index page (install_monitoring) gates on roxywi_auth.page_for_admin(level=2). Because the missing decorators omit both role and group checks, any logged-in user — including the default guest role 4 — can install/reconfigure exporters, WAF, and GeoIP databases on every server in the Roxy-WI database, regardless of tenant ownership. The Ansible playbooks run with the per-server SSH credential stored in Roxy-WI, which the credentials' rightful owner (a different tenant) has provisioned with sudo rights for the management workflow. At time of publication, there are no publicly available patches.

AI Analysis

Cross-tenant authorization bypass vulnerability in Roxy-WI, allowing any logged-in user to install/reconfigure exporters, WAF, and GeoIP databases on every server in the Roxy-WI database, regardless of tenant ownership.

Basic Information

ID CVE-2026-45552
Source GitHub_M
Published Jun 10, 2026 at 13:59

Affected Product

Vendor roxy-wi
Product roxy-wi
Version <= 8.2.6.4
Affected Versions roxy-wi roxy-wi <= 8.2.6.4

CWE Classification

AI Assessment

AI Score 9.9 / 10
AI Severity Critical
Vendor Roxy-WI
Product Roxy-WI
Version <= 8.2.6.4

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.