CVE-2026-33076
Roxy-WI vulnerable to path traversal and arbitrary file writing
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the haproxy_section_save interface presents a vulnerability that could lead to remote code execution due to path traversal and writing into scheduled tasks. Version 8.2.6.4 fixes the issue.
| CWE | CWE-22 |
| Vendor | roxy-wi |
| Product | roxy-wi |
| Published | Apr 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for roxy-wi roxy-wi
Be the first to know when new unknown vulnerabilities affecting roxy-wi roxy-wi are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
roxy-wi / roxy-wi
< 8.2.6.4