CVE-2026-27811: Roxy-Wi
High severity, CVSS 8.8. EPSS: 3% chance of exploitation in the next 30 days.
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.3, a command injection vulnerability exists in the `/config/compare/<service>/<server_ip>/show` endpoint, allowed authenticated users to execute arbitrary system commands on the app host. The vulnerability exists in `app/modules/config/config.py` on line 362, where user input is directly formatted in the template string that is eventually executed. Version 8.2.6.3 fixes the issue.
Affected products
- Roxy-Wi Roxy-Wi: before 8.2.6.3 (fixed in 8.2.6.3)
Published 2026-03-18. Last modified 2026-06-17.