Authorization bypass through user-controlled key in Roxy-WI - CVE-2026-45550
Published: May 16, 2026
Roxy-WI
Detailed vulnerability description
The vulnerability allows a remote user to modify monitoring checks across tenant boundaries.
The vulnerability exists due to incorrect authorization in the PUT /smon/check endpoint and downstream smon update functions when handling update requests with a user-controlled check_id. A remote user can send a specially crafted PUT request with another tenant's check_id to modify monitoring checks across tenant boundaries.
The issue affects HTTP, TCP, Ping, and DNS monitoring checks, and no user interaction is required.