OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-79316

HIGH · CVSS 7.6 EPSS 0.32% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-21 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

An improper access control vulnerability in x-ui 0.3.2 allows any authenticated panel user to modify the xray configuration template, resulting in a panel restart that exposes the management gRPC service to non-loopback addresses. This misconfiguration increases the attack surface by making the management interface accessible beyond its intended local-only scope. Organizations using x-ui should prioritize this issue to prevent potential unauthorized access to sensitive management functions.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-79316
Severity
HIGH
CVSS
7.6
EPSS
0.32%

Original NVD Description

An improper access control vulnerability exists in x-ui 0.3.2. Any authenticated panel user can modify the xray configuration template through the settings interface and trigger a panel restart, causing the xray management gRPC service, which is bound to loopback by default, to be regenerated and bound to non-loopback addresses. This expands the reachable surface of the management interface beyond its intended local-only boundary.