Executive brief
Roxy-WI is a management interface used to control web servers like Haproxy and Nginx. A security flaw allows any logged-in user, even those with guest-level access, to stop or restart critical monitoring services on any managed server. This could allow an attacker to disable security alerts or disrupt monitoring operations across different business units or customers.
Technical details
An authorization bypass exists in the `agent_action` function within `app/routes/smon/agent_routes.py`. The endpoint lacks role-based access control (RBAC) and group ownership validation on the `server_ip` parameter, requiring only a valid JWT. An authenticated attacker, including those with guest privileges (Role 4), can send a POST request to `/agent/action/<action>` to execute systemd commands. Because Roxy-WI uses stored SSH credentials with passwordless sudo to manage remote hosts, the commands are executed with root privileges on the target server. This can be used to cause a denial-of-service (DoS) of the monitoring pipeline or mask other malicious activities. As of publication, no official patches are available.
Affected products
- Roxy-WI Roxy-WI <= 8.2.6.4
Timeline
- 2026-05-15: advisory: GitHub Security Advisory published
- 2026-06-10: disclosed: CVE published to NVD