Vulnerabilities
CVE-2026-22265 - Roxy-WI has a Command Injection via grep parameter in logs.py allows authenticat
CVE ID : CVE-2026-22265 Published : Jan. 15, 2026, 5:16 p.m. | 49 minutes ago Description : Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to 8.2.8.2, command injection vulnerability exists in the log viewing functionality that allows authenticated users to execute arbitrary system commands. The vulnerability is in app/modules/roxywi/logs.py line 87, where the grep parameter is used twice - once sanitized and once raw. This vulnerability is fixed in 8.2.8.2. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE Details
Affected Product:
Nginx
Impact:
command injection
Source: Telegram CVE Monitor