PT-2026-48433 · Roxy-Wi · Roxy-Wi
CVE-2026-45549
·
Published
2026-06-10
·
Updated
2026-06-10
CVSS v3.1
8.5
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
Roxy-WI versions prior to 8.2.6.5
Description
An authentication bypass in the
agent action() function (located in app/routes/smon/agent routes.py) allows any authenticated user, including those with guest privileges, to perform unauthorized actions. The endpoint '/agent/action/' lacks role and group ownership verification for the server ip field. This allows a user to start, stop, or restart the roxy-wi-smon-agent systemd unit on any specified server. Because the application uses SSH credentials with passwordless sudo, these actions are executed with root privileges on the target system.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Missing Authorization
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Roxy-Wi