PT-2026-48434 · Roxy-Wi · Roxy-Wi
CVE-2026-45550
·
Published
2026-06-10
·
Updated
2026-06-10
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Roxy-WI versions prior to 8.2.6.5
Description
An authenticated user can modify monitoring checks belonging to other tenants. The endpoint "PUT /smon/check" uses the
roxywi common.check user group for flask() function, which only verifies that the user belongs to a group rather than confirming the specific check id belongs to that group. Consequently, the SQL update functions update smon(), update smonHttp(), update smonTcp(), update smonPing(), and update smonDns() execute updates based on smon id without a user group filter, allowing an attacker to iterate through smon id values and rewrite HTTP, TCP, Ping, or DNS monitoring checks.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Missing Authorization
IDOR
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Roxy-Wi