PT-2026-97917 · Termix · Termix
CVE-2026-79758
·
Published
2026-09-24
·
Updated
2026-09-24
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Termix versions 1.8.0 through 2.5.0
Description
Authenticated users can access the server-stats API without per-host authorization, failing to preserve tenant isolation. The affected routes in
src/backend/ssh/server-stats.ts allow users to view the online or offline state and lastChecked timestamps of hosts they are not authorized to access via the 'GET /status' and 'GET /status/:id' endpoints, where the latter accepts a numeric host identifier. Additionally, the 'POST /clear-connections' endpoint allows a regular user to clear the global SSH connection pool, which can disrupt active sessions or pooled connections of other users.Recommendations
Update to version 2.5.1.
Restrict access to the
src/backend/ssh/server-stats.ts routes as a temporary mitigation.Exploit
Fix
Improper Access Control
IDOR
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Termix