Arbitrary File Read Vulnerability in Roxy-WI Web Interface for Server Management
CVE-2026-33077
7.7HIGH
What is CVE-2026-33077?
Roxy-WI, a web interface designed for the management of Haproxy, Nginx, Apache, and Keepalived servers, contains an arbitrary file read vulnerability in the haproxy_section_save interface. This flaw could allow an unauthorized user to access sensitive files from the server. The vulnerability exists in versions prior to 8.2.6.4, which has since addressed this issue through an update. It is crucial to upgrade to the patched version to ensure server security and prevent potential data leakage.
Affected Version(s)
roxy-wi < 8.2.6.4
