
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27811 is a command injection vulnerability in Roxy-WI, a web interface for managing HAProxy, Nginx, Apache, and Keepalived servers. It affects all versions prior to 8.2.6.3 and allows authenticated users with low privileges to execute arbitrary system commands on the application host. The vulnerability was disclosed on March 17–18, 2026, with a fix released in version 8.2.6.3. It carries a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory).
The root cause is improper neutralization of special elements in an OS command (CWE-77, CWE-78), located in app/modules/config/config.py at line 362. The /config/compare/<service>/<server_ip>/show endpoint accepts left and right parameters representing configuration file names, which are directly interpolated into a shell command string: cmd = f"/bin/diff -ub {config_dir}{left} {config_dir}{right}". Because subprocess_execute calls subprocess.Popen with shell=True, an attacker can inject shell metacharacters (e.g., ; id; whoami; #) into the left or right parameters to break out of the intended diff command and execute arbitrary OS commands. The only prerequisite is authentication as any user with access to one of the supported services (haproxy, nginx, apache, keepalived) (GitHub Advisory, Patch Commit).
Successful exploitation grants an authenticated attacker arbitrary OS command execution on the Roxy-WI application host, which the advisory confirms typically runs as root (uid=0(root)). This results in full system compromise — including complete confidentiality, integrity, and availability loss — and allows the attacker to manipulate HAProxy, Nginx, Apache, and Keepalived configurations, potentially disrupting or redirecting traffic across managed infrastructure. The compromised host could also serve as a pivot point for lateral movement into the broader network (GitHub Advisory).
A complete, curl-based proof-of-concept exploit is publicly available in the GitHub Security Advisory, demonstrating authenticated RCE including login, CSRF token extraction, and command injection payload execution (GitHub Advisory). The EPSS score is approximately 0.0104 (~1%), and there is no current evidence of in-the-wild exploitation or CISA KEV catalog listing. No specific threat actor attribution has been reported. The low privilege requirement and network-accessible attack vector make this straightforward to exploit for any authenticated user.
curl -s -k -c session -X POST "http://TARGET/login" -H 'Content-Type: application/json' -d '{"login": "guest", "pass": "guest"}'CSRF=$(grep csrf session | awk '{print $7}')left parameter:curl -s -k -b session -X POST "http://TARGET/config/compare/haproxy/x/show" \
-H "X-CSRF-TOKEN: $CSRF" \
-H 'Content-Type: application/json' \
-d '{"left": "; id; whoami; #", "right": ""}'{"compare":"uid=0(root) gid=0(root) groups=0(root)\nroot"}), confirming full command execution (GitHub Advisory)./config/compare/<service>/<server_ip>/show containing shell metacharacters (;, |, &, #) in the JSON body left or right fields; outbound connections from the Roxy-WI host to unknown external IPs following such requests./config/compare/*/show with anomalous or encoded payloads in the request body; application logs reflecting unexpected command output or errors from diff_config.id, whoami, bash, curl, wget, python) visible via process monitoring tools like ps or auditd.Upgrade Roxy-WI to version 8.2.6.3 or later, which adds a check blocking .. in input values and wraps the compare logic in exception handling (Release v8.2.6.3, Patch Commit). As a workaround prior to patching, restrict network access to the Roxy-WI web interface to trusted administrators only using firewall rules or network segmentation. The advisory also recommends using shlex.quote to escape arguments and replacing subprocess.Popen(shell=True) calls with list-based argument passing to prevent shell injection (GitHub Advisory).
The vulnerability was reported by researcher flocto and published via GitHub's security advisory program. Social media activity includes posts on Infosec.Exchange and Bluesky referencing the CVE, and coverage appeared on threat intelligence aggregators such as The Hacker Wire and Yazoul. No major vendor statements or significant mainstream media coverage have been identified beyond the GitHub advisory and automated CVE feeds.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."