PT-2026-48437 · Haproxy+1 · Haproxy+1
CVE-2026-45558
·
Published
2026-06-10
·
Updated
2026-06-10
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Roxy-WI versions prior to 8.2.6.5
Description
An authenticated user with a role of 3 or lower can achieve remote code execution on managed load balancers. The issue exists because the HAProxy section-save endpoints, specifically 'POST /api/service/haproxy//section/
option field that is not validated or escaped. This input is rendered directly into the HAProxy configuration via the section.j2, global.j2, and defaults.j2 Ansible templates. By injecting arbitrary HAProxy directives, such as option external-check combined with an external-check command, an attacker can execute arbitrary commands as the haproxy user during every health-check tick.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
OS Command Injection
Command Injection
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Haproxy
Roxy-Wi