CVE-2026-33077

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the oldconfig parameter in the haproxy_section_save interface has an arbitrary file read vulnerability. Version 8.2.6.4 fixes the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:roxy-wi:roxy-wi:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-24 03:16

Updated : 2026-06-17 10:36


NVD link : CVE-2026-33077

Mitre link : CVE-2026-33077

CVE.ORG link : CVE-2026-33077


JSON object : View

Products Affected

roxy-wi

  • roxy-wi
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')