Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 21 Sep 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authenticated User Can Expand xray Management Service Reach Beyond Local Loopback in x-ui 0.3.2 | |
| First Time appeared |
Vaxilu
Vaxilu x-ui |
|
| Weaknesses | CWE-284 | |
| Vendors & Products |
Vaxilu
Vaxilu x-ui |
Mon, 21 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper access control vulnerability exists in x-ui 0.3.2. Any authenticated panel user can modify the xray configuration template through the settings interface and trigger a panel restart, causing the xray management gRPC service, which is bound to loopback by default, to be regenerated and bound to non-loopback addresses. This expands the reachable surface of the management interface beyond its intended local-only boundary. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-21T20:24:22.891Z
Reserved: 2026-08-25T00:00:00.000Z
Link: CVE-2026-79316
No data.
Status : Received
Published: 2026-09-21T21:17:12.100
Modified: 2026-09-21T21:17:12.100
Link: CVE-2026-79316
No data.
OpenCVE Enrichment
Updated: 2026-09-21T21:30:11Z