---
id: CVE-2026-79314
title: A horizontal privilege escalation vulnerability exists in x-ui 0.3.2
summary: >-
  A horizontal privilege escalation vulnerability exists in x-ui 0.3.2. An
  authenticated user can modify the inbound proxy configurations of other users,
  including remark, port, protocol, settings, enabled state, expiry time and
  traffic qu…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-284
published: '2026-09-22'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T00:16:35.950'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-79314'
references:
  - url: 'https://github.com/lichoin/TraceLoom/blob/main/CVEs/CVE-2026-79314.md'
    label: cve@mitre.org
  - url: 'https://github.com/vaxilu/x-ui'
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-25T23:17:33.095765Z'
epss: 0.00303
epssPercentile: 0.20663
ingestedAt: '2026-09-22T15:05:01.084Z'
---

## Overview

A horizontal privilege escalation vulnerability exists in x-ui 0.3.2. An authenticated user can modify the inbound proxy configurations of other users, including remark, port, protocol, settings, enabled state, expiry time and traffic quota, by submitting a request referencing the target resource identifier. The update path fails to verify that the target resource belongs to the requesting session user, allowing unauthorized cross-user modification of data.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
