CVE-2026-79314

vaxilu · x-ui

A horizontal privilege escalation vulnerability in x-ui 0.3.2 allows authenticated users to modify the inbound proxy configurations of other users by manipulating resource identifiers.

Executive summary

An authenticated horizontal privilege escalation vulnerability in x-ui version 0.3.2 allows unauthorized users to modify proxy settings belonging to other accounts, posing a significant risk to service integrity.

Vulnerability

This is a horizontal privilege escalation flaw where the update mechanism fails to perform proper authorization checks. An authenticated user can exploit this by submitting requests that target resource identifiers belonging to other users, granting them unauthorized control over proxy configurations.

Business impact

The ability for an authenticated user to modify another user's proxy settings can lead to complete service disruption, unauthorized traffic interception, or the theft of sensitive proxy resources. With a CVSS score of 8.8, this vulnerability is classified as high severity, as it directly compromises the confidentiality, integrity, and availability of the user environment and associated network traffic.

Remediation

Immediate Action: Since a specific patch version is not currently identified, users should restrict access to the x-ui management interface to trusted administrative networks and review all user account permissions.

Proactive Monitoring: Monitor access logs for suspicious API requests where a single session identifier is linked to multiple resource modifications that do not align with assigned user scopes.

Compensating Controls: Implement a Web Application Firewall (WAF) to inspect incoming requests for anomalous resource ID patterns or unauthorized modifications to proxy configuration endpoints.

Exploitation status

Public Exploit Available: Yes — a published proof-of-concept exists in the researcher write-up referenced by the CVE record.

Analyst recommendation

Given the high CVSS score and the existence of a public proof-of-concept, organizations utilizing x-ui 0.3.2 must prioritize the mitigation of this flaw. Administrators should monitor the project repository for an official security update and apply it immediately upon release to prevent unauthorized account takeover and proxy configuration tampering.

More vaxilu CVEs

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 8.8 (3.1) from gemini-grounded
  4. Analyst report written

Sources