{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/3x-ui-v3--3.3.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-55477"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["3x-ui (v3 \u003c= 3.3.0)","3x-ui (v2 \u003c= 2.9.4)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Mhsanaei"],"content_html":"\u003cp\u003eThe 3x-ui panel is vulnerable to an arbitrary file write vulnerability, tracked as CVE-2026-55477, which allows an authenticated administrator to manipulate the system configuration. By modifying the \u003ccode\u003exrayTemplateConfig.log.access\u003c/code\u003e setting - either through the database import functionality or the built-in raw Xray configuration editor - an attacker can redirect Xray's access logs to an arbitrary file path on the host filesystem.\u003c/p\u003e\n\u003cp\u003eWhen a connection is processed, content injected into an inbound client's 'email' field is written to the configured log destination. Because this allows writing to sensitive system files (such as \u003ccode\u003e.ssh/authorized_keys\u003c/code\u003e or configuration files), an attacker with administrative access to the panel can achieve code execution or gain persistent access, inheriting the privileges of the user running the Xray process. If Xray is deployed with root privileges, this results in full host compromise. The vulnerability is addressed in version 3.3.1, which confines log paths to the application's log directory.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker authenticates to the 3x-ui web panel as an administrator.\u003c/li\u003e\n\u003cli\u003eAttacker accesses the raw configuration editor or prepares a modified SQLite database file for import.\u003c/li\u003e\n\u003cli\u003eAttacker modifies the \u003ccode\u003exrayTemplateConfig.log.access\u003c/code\u003e parameter to target a sensitive system file (e.g., \u003ccode\u003e/root/.ssh/authorized_keys\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eAttacker creates or modifies an inbound client configuration, setting the 'email' field to contain a malicious payload (e.g., an SSH public key).\u003c/li\u003e\n\u003cli\u003eAttacker saves the configuration or imports the malicious database into the 3x-ui panel.\u003c/li\u003e\n\u003cli\u003eAttacker triggers an inbound connection to the panel through the modified client configuration.\u003c/li\u003e\n\u003cli\u003eThe Xray process processes the connection and writes the malicious payload from the 'email' field into the target file.\u003c/li\u003e\n\u003cli\u003eAttacker leverages the modified system file to gain shell access or achieve persistent code execution on the host.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows any authenticated administrator to overwrite or create files with the privileges of the Xray process. Successful exploitation can result in full host compromise, particularly in deployments where Xray runs with elevated (root) privileges. This affects all 3x-ui instances running versions 3.3.0 and earlier (v3 branch) or 2.9.4 and earlier (v2 branch).\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade 3x-ui to version 3.3.1 or later immediately to apply path confinement.\u003c/li\u003e\n\u003cli\u003eAudit administrative access to the 3x-ui panel; ensure only highly trusted users possess administrative privileges.\u003c/li\u003e\n\u003cli\u003eReview filesystem permissions to ensure the Xray process runs with the least privilege necessary, preventing it from writing to sensitive directories outside of its own log folder.\u003c/li\u003e\n\u003cli\u003eMonitor logs for unauthorized or unexpected modifications to sensitive files such as \u003ccode\u003e.ssh/authorized_keys\u003c/code\u003e or system cron directories.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-24T21:57:43Z","date_published":"2026-08-24T21:57:43Z","id":"https://feed.craftedsignal.io/briefs/2026-08-3x-ui-arbitrary-file-write/","summary":"An authenticated administrator in 3x-ui can abuse log configuration settings to achieve arbitrary file writes, potentially leading to persistent access or code execution as the Xray process user.","title":"Authenticated Arbitrary File Write in 3x-ui via Xray Log Path Manipulation","url":"https://feed.craftedsignal.io/briefs/2026-08-3x-ui-arbitrary-file-write/"}],"language":"en","title":"CraftedSignal Threat Feed - 3x-Ui (V3 \u003c= 3.3.0)","version":"https://jsonfeed.org/version/1.1"}