PT-2026-48435 · Roxy-Wi · Roxy-Wi
CVE-2026-45552
·
Published
2026-06-10
·
Updated
2026-06-10
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Roxy-WI versions prior to 8.2.6.4
Description
Insufficient access control in the install blueprint allows any logged-in user, including those with the default guest role, to install or reconfigure exporters, WAF, and GeoIP databases on any server in the database, regardless of tenant ownership. This occurs because several endpoints are not wrapped in the required administrative checks and fail to verify if a user has access to a specific server group. The affected endpoints include 'install exporter', 'install waf', 'install geoip', 'check geoip', 'get exporter version', and 'get task status'. Exploitation leverages Ansible playbooks running with SSH credentials that may have sudo rights, potentially leading to remote code execution.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Restrict network access to the affected endpoints to minimize the risk of exploitation.
Exploit
RCE
Missing Authorization
IDOR
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Roxy-Wi