{"id":"CVE-2026-79316","title":"An improper access control vulnerability exists in x-ui 0.3.2","summary":"An improper access control vulnerability exists in x-ui 0.3.2. Any authenticated panel user can modify the xray configuration template through the settings interface and trigger a panel restart, causing the xray management gRPC service, …","severity":"high","cvss":7.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L","cwe":["CWE-284"],"published":"2026-09-21","updated":"2026-09-22","sourceUpdated":"2026-09-22T20:00:03.713","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-79316","references":[{"url":"https://github.com/lichoin/TraceLoom/blob/main/CVEs/CVE-2026-79316.md","label":"cve@mitre.org"},{"url":"https://github.com/vaxilu/x-ui","label":"cve@mitre.org"}],"tags":["nvd","cve.org"],"epss":0.00234,"epssPercentile":0.14647,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-22T14:46:38.598501Z"},"ingestedAt":"2026-09-21T20:52:58.299Z","slug":"CVE-2026-79316","body":"## Overview\n\nAn improper access control vulnerability exists in x-ui 0.3.2. Any authenticated panel user can modify the xray configuration template through the settings interface and trigger a panel restart, causing the xray management gRPC service, which is bound to loopback by default, to be regenerated and bound to non-loopback addresses. This expands the reachable surface of the management interface beyond its intended local-only boundary.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":41.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":209087,"id":"CVE-2026-79316","ts":1790089536461,"field":"cvss","old":null,"new":"7.6"},{"seq":209086,"id":"CVE-2026-79316","ts":1790089536461,"field":"severity","old":"none","new":"high"}]}