PT-2026-48435 · Roxy-Wi · Roxy-Wi

CVE-2026-45552

·

Published

2026-06-10

·

Updated

2026-06-10

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Roxy-WI versions prior to 8.2.6.4
Description Insufficient access control in the install blueprint allows any logged-in user, including those with the default guest role, to install or reconfigure exporters, WAF, and GeoIP databases on any server in the database, regardless of tenant ownership. This occurs because several endpoints are not wrapped in the required administrative checks and fail to verify if a user has access to a specific server group. The affected endpoints include 'install exporter', 'install waf', 'install geoip', 'check geoip', 'get exporter version', and 'get task status'. Exploitation leverages Ansible playbooks running with SSH credentials that may have sudo rights, potentially leading to remote code execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Restrict network access to the affected endpoints to minimize the risk of exploitation.

Exploit

RCE

Missing Authorization

IDOR

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45552
GHSA-V3F8-G2V8-JQ5H

Affected Products

Roxy-Wi