PT-2026-97917 · Termix · Termix

CVE-2026-79758

·

Published

2026-09-24

·

Updated

2026-09-24

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions Termix versions 1.8.0 through 2.5.0
Description Authenticated users can access the server-stats API without per-host authorization, failing to preserve tenant isolation. The affected routes in src/backend/ssh/server-stats.ts allow users to view the online or offline state and lastChecked timestamps of hosts they are not authorized to access via the 'GET /status' and 'GET /status/:id' endpoints, where the latter accepts a numeric host identifier. Additionally, the 'POST /clear-connections' endpoint allows a regular user to clear the global SSH connection pool, which can disrupt active sessions or pooled connections of other users.
Recommendations Update to version 2.5.1. Restrict access to the src/backend/ssh/server-stats.ts routes as a temporary mitigation.

Exploit

Fix

Improper Access Control

IDOR

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-79758
GHSA-372W-6F3H-VCM4

Affected Products

Termix