CVE-2026-79316
Received Received - Intake

Improper Access Control in x-ui Panel Allows Configuration Tampering

Vulnerability report for CVE-2026-79316, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-21

Last updated on: 2026-09-21

Assigner: MITRE

Description

An improper access control vulnerability exists in x-ui 0.3.2. Any authenticated panel user can modify the xray configuration template through the settings interface and trigger a panel restart, causing the xray management gRPC service, which is bound to loopback by default, to be regenerated and bound to non-loopback addresses. This expands the reachable surface of the management interface beyond its intended local-only boundary.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-21
Last Modified
2026-09-21
Generated
2026-09-22
AI Q&A
2026-09-22
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an improper access control issue in x-ui version 0.3.2. An authenticated user with panel access can modify the xray configuration template via the settings interface and force a panel restart. This causes the xray management gRPC service, which normally binds only to loopback addresses, to regenerate and bind to non-loopback addresses. This expands the management interface's reachable surface beyond its intended local-only boundary.

Impact Analysis

This vulnerability allows an attacker with authenticated panel access to expose the xray management interface to non-loopback addresses. This could enable remote attackers to interact with the management interface, potentially leading to unauthorized configuration changes, service disruption, or further exploitation of the system.

Compliance Impact

This vulnerability could potentially violate compliance with standards like GDPR and HIPAA by exposing the xray management interface to non-loopback addresses. This expansion of the reachable surface may allow unauthorized access to sensitive data or management functions, increasing the risk of data breaches or unauthorized modifications.

Mitigation Strategies

Immediately restrict access to the x-ui panel to authorized users only. Review and update firewall rules to block external access to the xray management gRPC service. Disable or remove the x-ui panel if not required. Monitor network traffic for unusual connections to the management interface.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-79316. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart