Executive brief
x-ui is a web panel that manages Xray proxy services for remote administration. An authenticated user can modify the Xray configuration template to rebind the management interface from localhost to any network address, then trigger a restart to expose the administrative service to the network. This allows any user with panel login credentials to access or manipulate the proxy service management interface beyond its intended local-only scope.
Technical details
The vulnerability stems from improper access control (CWE-284) combined with unsafe configuration handling. An authenticated panel user can edit the Xray configuration template in settings (which performs only JSON syntax validation, not security constraints) and trigger a panel restart; the template is then applied verbatim to regenerate the runtime configuration, causing the management gRPC interface to bind to a non-loopback address. An attacker with valid panel credentials can exploit this without administrator privileges, requiring only a restart event to activate the malicious configuration.
Affected products
- vaxilu x-ui 0.3.2
Timeline
- 2026-09-21: disclosed
- 2026-08-04: other: Report date