CVE-2026-79316: X-ui vulnerability

Published Sep 21, 2026
·
Updated

An improper access control vulnerability exists in x-ui 0.3.2. Any authenticated panel user can modify the xray configuration template through the settings interface and trigger a panel restart, causing the xray management gRPC service, which is bound to loopback by default, to be regenerated and bound to non-loopback addresses. This expands the reachable surface of the management interface beyond its intended local-only boundary.

Affected Software

1 affected component
x-ui=0.3.2

Event History

Sep 21, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:17 PM
Description

Frequently Asked Questions

1

Who can exploit this issue?

Any authenticated x-ui panel user can exploit it. The described action is performed through the settings interface and does not require direct local access to the host.

2

What attacker access is required to expose the management service beyond loopback?

The attacker needs an authenticated panel account with access to modify the xray configuration template through x-ui settings and trigger a panel restart.

3

Is the default management-service binding directly exposed?

No. The management gRPC service is bound to loopback by default; exposure occurs after an authenticated user changes the template and restarts the panel, causing it to be regenerated with non-loopback bindings.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203