CVE-2026-45563

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, GET /history/<service>/<server_ip> re-uses the server_ip path parameter as a user-id when service == 'user', with no authorization check. Any authenticated user — even a guest in an unrelated group — can list any other user's full action audit trail (server IPs touched, configs deployed, services restarted). At time of publication, there are no publicly available patches.
Configurations

No configuration.

History

10 Jun 2026, 16:17

Type Values Removed Values Added
References () https://github.com/roxy-wi/roxy-wi/security/advisories/GHSA-wcmc-cjmw-54x9 - () https://github.com/roxy-wi/roxy-wi/security/advisories/GHSA-wcmc-cjmw-54x9 -

10 Jun 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-10 15:16

Updated : 2026-06-10 19:37


NVD link : CVE-2026-45563

Mitre link : CVE-2026-45563

CVE.ORG link : CVE-2026-45563


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key

CWE-863

Incorrect Authorization