CVE-2026-55477
HIGHAuthenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation
Title source: cnaDescription
3X-UI is a web control panel for managing Xray-core servers. Prior to 3.3.1, an authenticated administrator can abuse the database import functionality to achieve arbitrary file write on the host by modifying Xray configuration values stored in the database. This can be leveraged to obtain code execution and persistent access as the user running Xray (including root when Xray is running as root). This vulnerability is fixed in 3.3.1.
References (1)
Core 1
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/MHSanaei/3x-ui/security/advisories/GHSA-jm48-m3rr-9hgg
Scores
CVSS v3
7.2
EPSS
0.0034
EPSS Percentile
26.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-73
Status
published
Products (1)
MHSanaei/3x-ui
< 3.3.1
Published
Jun 25, 2026
Tracked Since
Jun 25, 2026