PT-2026-48433 · Roxy-Wi · Roxy-Wi

CVE-2026-45549

·

Published

2026-06-10

·

Updated

2026-06-10

CVSS v3.1

8.5

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions Roxy-WI versions prior to 8.2.6.5
Description An authentication bypass in the agent action() function (located in app/routes/smon/agent routes.py) allows any authenticated user, including those with guest privileges, to perform unauthorized actions. The endpoint '/agent/action/' lacks role and group ownership verification for the server ip field. This allows a user to start, stop, or restart the roxy-wi-smon-agent systemd unit on any specified server. Because the application uses SSH credentials with passwordless sudo, these actions are executed with root privileges on the target system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authorization

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45549
GHSA-C92J-H72M-FF4J

Affected Products

Roxy-Wi