Search Results (3 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-79317 1 Vaxilu 1 X-ui 2026-09-21 N/A
A session invalidation flaw exists in x-ui 0.3.2. The full user object is stored in a client-side signed cookie, and authentication only checks that a user object can be retrieved from the cookie without re-validating against the database or any session version. When an administrator changes the username or password, previously issued session cookies are not revoked, so an attacker who holds a pre-change admin cookie can continue accessing and operating the management interface after the credentials have been rotated.
CVE-2026-79316 1 Vaxilu 1 X-ui 2026-09-21 N/A
An improper access control vulnerability exists in x-ui 0.3.2. Any authenticated panel user can modify the xray configuration template through the settings interface and trigger a panel restart, causing the xray management gRPC service, which is bound to loopback by default, to be regenerated and bound to non-loopback addresses. This expands the reachable surface of the management interface beyond its intended local-only boundary.
CVE-2023-41595 1 Vaxilu 1 X-ui 2024-11-21 7.5 High
An issue in xui-xray v1.8.3 allows attackers to obtain sensitive information via default password.