Junglewise Threat Intelligence

CVE-2026-45569: Roxy-WI path traversal in configuration management

CVE-2026-45569 · Severity: high · CVSS 8.1 · Published 2026-06-10

Technologies: Roxy-WI. Vendors: Roxy-WI.

Executive brief

Roxy-WI, a management interface for popular web servers like Nginx and HAProxy, contains a flaw that allows authenticated users to access sensitive files on the host server. Due to an ineffective security check, an attacker can bypass directory restrictions to read critical data, including private encryption keys and stored credentials. This could lead to full system compromise or the ability to impersonate other users.

Technical details

A path traversal vulnerability exists in Roxy-WI versions 8.2.6.4 and prior within `app/modules/config/config.py`. The root cause is an incorrect comparison (CWE-697) where the application uses tuple-membership testing (`'..' in (a, b, c)`) instead of substring containment checking. This logic only triggers if a variable is exactly equal to '..', failing to block standard traversal sequences like `../../etc/passwd`. An authenticated attacker with at least low-level privileges can provide a crafted `configver` parameter via the `/config/versions/` route to perform an arbitrary file read. This can be used to exfiltrate the JWT signing key (`roxy-wi-key`) or SSH private keys. No public patch was available at the time of the advisory.

Affected products

  • Roxy-WI Roxy-WI <= 8.2.6.4

Timeline

  • 2026-05-15: advisory: GHSA-j6p4-8532-h9hv published
  • 2026-06-10: disclosed: CVE-2026-45569 published to NVD

References

Related threats