Executive brief
x-ui is a web-based proxy management panel used by administrators to configure and control proxy services across multiple user accounts. An authenticated user can delete or modify proxy configurations belonging to other users by directly referencing their configuration identifiers, effectively taking down another account's service or destroying their configuration. This horizontal privilege escalation requires only basic user credentials and knowledge of target configuration IDs, making it a significant risk in shared deployments.
Technical details
The vulnerability is an authorization bypass (CWE-639) in the inbound configuration deletion operation: the endpoint accepts a record identifier from the request and deletes it without verifying that the record belongs to the authenticated user's account. The deletion path lacks the ownership check present in other inbound-related operations (listing, creation, modification), allowing cross-account data destruction. The issue requires authentication but no special privileges, administrator access, or user interaction; exploitation only requires knowledge of a target configuration ID.
Affected products
- vaxilu x-ui 0.3.2 and later development branch
Timeline
- 2026-09-22: disclosed: Public disclosure via NVD
- 2026-08-04: other: Vulnerability reported and confirmed by reproduction