OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-79314

HIGH · CVSS 8.8 EPSS 0.30% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-22 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

A horizontal privilege escalation vulnerability allows authenticated users of x-ui 0.3.2 to alter the inbound proxy configurations of other users, including critical settings such as ports and traffic quotas. This flaw arises from the system's failure to verify the ownership of the target resource, enabling unauthorized data modifications across user sessions. Organizations using this software should prioritize remediation to prevent potential abuse of user configurations and maintain data integrity.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-79314
Severity
HIGH
CVSS
8.8
EPSS
0.30%

Original NVD Description

A horizontal privilege escalation vulnerability exists in x-ui 0.3.2. An authenticated user can modify the inbound proxy configurations of other users, including remark, port, protocol, settings, enabled state, expiry time and traffic quota, by submitting a request referencing the target resource identifier. The update path fails to verify that the target resource belongs to the requesting session user, allowing unauthorized cross-user modification of data.