CVE-2026-33077: Roxy-WI has an arbitrary file read vulnerability
Published Apr 24, 2026
·Updated
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the oldconfig parameter in the haproxysectionsave interface has an arbitrary file read vulnerability. Version 8.2.6.4 fixes the issue.
Affected Software
2 affected components
Roxy-WI Roxy-wi<8.2.6.4
Roxy-WI Roxy-wi<8.2.6.4
Remediation
Event History
Apr 24, 2026
CVE Published
via MITRE·01:55 AM
Data Sourced
via MITRE·01:55 AM
DescriptionWeakness
Data Sourced
via NVD·03:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-33077?
CVE-2026-33077 is classified as a high-severity vulnerability due to its potential impact on system confidentiality.
2
How do I fix CVE-2026-33077?
To fix CVE-2026-33077, update Roxy-WI to version 8.2.6.4 or later.
3
What does CVE-2026-33077 affect?
CVE-2026-33077 affects Roxy-WI versions prior to 8.2.6.4.
4
What type of vulnerability is CVE-2026-33077?
CVE-2026-33077 is an arbitrary file read vulnerability.
5
What components are involved in CVE-2026-33077?
CVE-2026-33077 involves the haproxy_section_save interface in Roxy-WI.