Junglewise Threat Intelligence

CVE-2026-45563: Roxy-WI authorization bypass in history endpoint

CVE-2026-45563 · Severity: medium · CVSS 4.3 · Published 2026-06-10

Technologies: Roxy-WI. Vendors: Roxy-WI.

Executive brief

Roxy-WI is a web-based management tool used to configure and control Haproxy, Nginx, Apache, and Keepalived servers. A security flaw allows any logged-in user, including those with restricted guest access, to view the full activity history of any other user on the system. This exposure reveals sensitive operational data, such as which servers were accessed and when configuration changes were made, which could be used to plan more targeted attacks.

Technical details

An Insecure Direct Object Reference (IDOR) exists in the `/history/<service>/<server_ip>` endpoint. When the `service` parameter is set to 'user', the application re-uses the `server_ip` path parameter as a `user-id` to fetch audit logs without performing an authorization check or group-access validation. An authenticated attacker (even with guest privileges) can provide an arbitrary user ID to retrieve that user's action history, including server IPs touched, configurations deployed, and services restarted. As of the advisory date, no official patch has been released, though manual code remediation involving `page_for_admin` and `is_user_has_access_to_its_group` checks has been suggested.

Affected products

  • Roxy-WI Roxy-WI <= 8.2.6.4

Timeline

  • 2026-05-15: advisory: GitHub Security Advisory published
  • 2026-06-10: disclosed: CVE published to NVD

References

Related threats