OS Command Injection in Roxy-WI - CVE-2026-27811
Published: April 20, 2026
Roxy-WI
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary commands on the app host.
The vulnerability exists due to command injection in the /config/compare///show endpoint when processing the left and right parameters for configuration comparison. A remote user can send specially crafted left and right values to execute arbitrary commands on the app host.
Exploitation requires access to one of the supported services with a configuration directory: haproxy, nginx, apache, or keepalived.