An improper access control vulnerability exists in x-ui 0.3.2. Any authenticated panel user can modify the xray configuration template through the settings interface and trigger a panel restart, causing the xray management gRPC service, which is bound to loopback by default, to be regenerated and bound to non-loopback addresses. This expands the reachable surface of the management interface beyond its intended local-only boundary.

Project Subscriptions

Vendors Products
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 21 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Title Authenticated User Can Expand xray Management Service Reach Beyond Local Loopback in x-ui 0.3.2
First Time appeared Vaxilu
Vaxilu x-ui
Weaknesses CWE-284
Vendors & Products Vaxilu
Vaxilu x-ui

Mon, 21 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description An improper access control vulnerability exists in x-ui 0.3.2. Any authenticated panel user can modify the xray configuration template through the settings interface and trigger a panel restart, causing the xray management gRPC service, which is bound to loopback by default, to be regenerated and bound to non-loopback addresses. This expands the reachable surface of the management interface beyond its intended local-only boundary.
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-21T20:24:22.891Z

Reserved: 2026-08-25T00:00:00.000Z

Link: CVE-2026-79316

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-21T21:17:12.100

Modified: 2026-09-21T21:17:12.100

Link: CVE-2026-79316

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T21:30:11Z

Weaknesses