LDAP injection in Roxy-WI - CVE-2026-45559
Published: May 16, 2026
Roxy-WI
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to ldap injection in get_ldap_email in app/modules/roxywi/user.py when processing the username URL path parameter in the /user/ldap/
The issue is limited to the admin-only endpoint and can expose LDAP attributes outside the intended record.