CVE-2026-55477 Details
Description
3X-UI is a web control panel for managing Xray-core servers. Prior to 3.3.1, an authenticated administrator can abuse the database import functionality to achieve arbitrary file write on the host by modifying Xray configuration values stored in the database. This can be leveraged to obtain code execution and persistent access as the user running Xray (including root when Xray is running as root). This vulnerability is fixed in 3.3.1.
A vulnerability in 3X-UI, a web control panel for managing Xray-core servers, allows authenticated administrators to perform arbitrary file writes on the host. This issue exists in versions prior to 3.3.1. The vulnerability arises from the database import functionality, which inadequately validates configuration values. By exploiting this flaw, an administrator can modify Xray log path settings to point to a writable file, such as the SSH authorized keys file. Once the database is imported, the injected content is written to the specified file, potentially leading to code execution and persistent access as the user running Xray, including root access if Xray is executed as root.
Users are advised to upgrade to version 3.3.1, where this vulnerability has been fixed. The update restricts the Xray log path values to the panel's log folder, preventing unauthorized file writes outside of designated areas. Until the update can be applied, it is recommended to limit panel administrator access to trusted individuals.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 25, 2026CISA-ADP
Assessed Jun 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/MHSanaei/3x-ui/security/advisories/GHSA-jm48-m3rr-9hgg | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://github.com/MHSanaei/3x-ui/security/advisories/GHSA-jm48-m3rr-9hgg | [email protected] | AdvisoryExploitRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-73 | External Control of File Name or Path | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| MHSanaei 3X-UI | <= 3.3.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 25, 2026 | CVE Modified | CISA-ADP |
| Jun 25, 2026 | New CVE Received | [email protected] |
Volerion