CVE-2026-33529 details an authenticated path traversal vulnerability in Zoraxy, an HTTP reverse proxy, affecting versions prior to 3.3.2. This flaw allows an authenticated user to write arbitrary files outside the config directory, potentially leading to Remote Code Execution (RCE) by creating a malicious plugin. With a CVSS score of 8.8 (High), the vulnerability has a network attack vector and low attack complexity, requiring only low privileges for exploitation. While it is on an active "Hot List" and has seen limited community discussion, there is currently no public exploit code available, and it is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.3.2CPE matchmatch criteria | cpe:2.3:a:zoraxy:zoraxy:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.