IWX-CVE-2026-15427 (2026-09-17) =============================== InterWorx has identified a new local privilege escalation vulnerability in the legacy cluster API. Any authenticated panel user, including a SiteWorx account holder, could invoke privileged cluster management calls that are intended only for the root user. InterWorx has released hotfixes to correct this vulnerability. This vulnerability is considered critical, and has been exploited in the wild. All InterWorx users are strongly encouraged to upgrade to the latest version, or confirm that the hotfix has been applied. .. contents:: Affected InterWorx Versions --------------------------- - All InterWorx 6 <= 6.14.5 - All InterWorx 7 <= 7.14.4 - All InterWorx 8 <= 8.2.15 Hotfixes Available ------------------ - interworx-hotfix-6.14.1.2344-55.noarch.rpm - interworx-hotfix-6.14.5.2593-33.noarch.rpm - interworx-hotfix-7.13.34.2685-2.noarch.rpm - interworx-hotfix-7.13.35.2712-4.noarch.rpm - interworx-hotfix-7.14.4.3227-12.noarch.rpm - interworx-hotfix-8.0.25.2893-11.noarch.rpm - interworx-hotfix-8.1.11.3065-2.noarch.rpm - interworx-hotfix-8.2.0.3152-8.noarch.rpm - interworx-hotfix-8.2.10.3225-5.noarch.rpm - interworx-hotfix-8.2.15.3239-7.noarch.rpm Installation and Verification ----------------------------- On a standard InterWorx installation, hotfixes are automatically applied every 6 hours. To verify if a system has been patched: #. Log in to the server at the CLI as root, either via SSH or from the terminal #. At the CLI, run the following command, and compare the output to the list above: .. code-block:: rpm -q interworx-hotfix #. If the version listed in the command output is not in the list above, run the following to attempt to install the latest hotfix: .. code-block:: ~iworx/bin/hotfix.pex --install --force #. Check the list, again .. code-block:: rpm -q interworx-hotfix If the hotfix version in the command output is still not one found in the above list, please :doc:`enable Remote Assistance ` and then `open a support ticket with InterWorx support `__.