Junglewise Threat Intelligence

CVE-2026-45559: Roxy-WI LDAP injection in get_ldap_email

CVE-2026-45559 · Severity: medium · CVSS 4.9 · Published 2026-06-10

Technologies: Roxy-WI. Vendors: Roxy-WI.

Executive brief

Roxy-WI, a management interface for server software like Nginx and HAProxy, contains a security flaw in how it handles LDAP directory searches. An administrative user can bypass intended restrictions to view sensitive information or list records from the organization's LDAP directory that they should not be able to access. This could lead to the exposure of employee contact details or other internal directory data.

Technical details

An LDAP injection vulnerability exists in Roxy-WI versions 8.2.6.4 and prior within the `get_ldap_email` function located in `app/modules/roxywi/user.py`. The application constructs LDAP search filters using f-string concatenation with the `username` URL path parameter without performing input validation or LDAP escaping. An attacker with high privileges (Level 2 Admin/Group Admin) can inject LDAP metacharacters (e.g., `*)(mail=*)(cn=*`) to manipulate the query logic. This allows for the enumeration and harvesting of LDAP attributes outside the intended scope of the single user record. As of the advisory date, no official patches are available, though manual remediation involves using `ldap.filter.escape_filter_chars`.

Affected products

  • Roxy-WI Roxy-WI <= 8.2.6.4

Timeline

  • 2026-05-15: advisory: GitHub Security Advisory published
  • 2026-06-10: disclosed: CVE published to NVD

References

Related threats