PT-2026-33846 · Roxy-Wi · Roxy-Wi

Published

2026-04-20

·

Updated

2026-04-21

·

CVE-2026-33432

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Roxy-WI versions prior to 8.2.8.3
Description When LDAP authentication is enabled, the application constructs an LDAP search filter by directly concatenating the user-supplied username into the filter string without escaping special characters. This allows an unauthenticated attacker to inject LDAP filter metacharacters into the username field to manipulate the search query and cause the directory to return an unintended user entry, resulting in a complete authentication bypass.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33432

Affected Products

Roxy-Wi