← Back to search

CVE-2026-79314

8.8 HIGHpublic exploit available

Published 2026-09-22 · Updated 2026-09-26

AI risk analysis

Summary
A vulnerability allows an authenticated user to modify the inbound proxy configurations of other users, leading to unauthorized data modification.
Exploitability
Exploitation requires authentication and knowledge of the target user's resource identifier, making it moderately difficult.
Blast radius
If exploited, this could lead to significant data loss or misconfiguration affecting multiple users.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to x-ui 0.3.3 or later.
auth-bypassconfig-mgmtpriv-escalation

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

A horizontal privilege escalation vulnerability exists in x-ui 0.3.2. An authenticated user can modify the inbound proxy configurations of other users, including remark, port, protocol, settings, enabled state, expiry time and traffic quota, by submitting a request referencing the target resource identifier. The update path fails to verify that the target resource belongs to the requesting session user, allowing unauthorized cross-user modification of data.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-284

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.