Executive brief
Roxy-WI, a management interface for server software like Nginx and HAProxy, contains a security flaw in how it handles LDAP directory searches. An administrative user can bypass intended restrictions to view sensitive information or list records from the organization's LDAP directory that they should not be able to access. This could lead to the exposure of employee contact details or other internal directory data.
Technical details
An LDAP injection vulnerability exists in Roxy-WI versions 8.2.6.4 and prior within the `get_ldap_email` function located in `app/modules/roxywi/user.py`. The application constructs LDAP search filters using f-string concatenation with the `username` URL path parameter without performing input validation or LDAP escaping. An attacker with high privileges (Level 2 Admin/Group Admin) can inject LDAP metacharacters (e.g., `*)(mail=*)(cn=*`) to manipulate the query logic. This allows for the enumeration and harvesting of LDAP attributes outside the intended scope of the single user record. As of the advisory date, no official patches are available, though manual remediation involves using `ldap.filter.escape_filter_chars`.
Affected products
- Roxy-WI Roxy-WI <= 8.2.6.4
Timeline
- 2026-05-15: advisory: GitHub Security Advisory published
- 2026-06-10: disclosed: CVE published to NVD