CVE-2026-22265 - Roxy-WI has a Command Injection via grep parameter in logs.py allows authenticat

CVE-2026-22265 - Roxy-WI has a Command Injection via grep parameter in logs.py allows authenticat

CVE ID : CVE-2026-22265 Published : Jan. 15, 2026, 5:16 p.m. | 49 minutes ago Description : Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to 8.2.8.2, command injection vulnerability exists in the log viewing functionality that allows authenticated users to execute arbitrary system commands. The vulnerability is in app/modules/roxywi/logs.py line 87, where the grep parameter is used twice - once sanitized and once raw. This vulnerability is fixed in 8.2.8.2. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
HIGH
Published
Jan. 15, 2026
Affected Product: Nginx
Impact: command injection

Source: Telegram CVE Monitor