PT-2026-48438 · Roxy-Wi · Roxy-Wi

Published

2026-06-10

·

Updated

2026-06-10

·

CVE-2026-45559

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, get ldap email (app/modules/roxywi/user.py:120-157) builds the LDAP search filter via f-string concatenation. The username URL path parameter is taken verbatim — no checkAjaxInput, no LDAP escape — and inserted, a username like )(mail=)(cn=* injects additional clauses, allowing the admin to enumerate or harvest attributes outside the intended record. At time of publication, there are no publicly available patches.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-45559

Affected Products

Roxy-Wi