CVE-2026-33076: Roxy-WI vulnerable to path traversal and arbitrary file writing
Published Apr 24, 2026
·Updated
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the haproxysectionsave interface presents a vulnerability that could lead to remote code execution due to path traversal and writing into scheduled tasks. Version 8.2.6.4 fixes the issue.
Affected Software
2 affected components
Roxy-WI Roxy-wi<8.2.6.4
Roxy-WI Roxy-wi<8.2.6.4
Remediation
Event History
Apr 24, 2026
CVE Published
via MITRE·01:52 AM
Data Sourced
via MITRE·01:52 AM
DescriptionWeakness
Data Sourced
via NVD·03:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-33076?
CVE-2026-33076 has a high severity level due to its potential for remote code execution.
2
How do I fix CVE-2026-33076?
To fix CVE-2026-33076, update Roxy-WI to version 8.2.6.4 or later.
3
What type of vulnerability is CVE-2026-33076?
CVE-2026-33076 is a path traversal and arbitrary file writing vulnerability.
4
Who is affected by CVE-2026-33076?
Users of Roxy-WI versions prior to 8.2.6.4 are affected by CVE-2026-33076.
5
What can attackers do with CVE-2026-33076?
Attackers can exploit CVE-2026-33076 to perform remote code execution on the affected systems.