PT-2026-97918 · Termix · Termix

CVE-2026-79759

·

Published

2026-09-24

·

Updated

2026-09-29

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Termix versions 1.7.0 through 2.5.0
Description Termix is a web-based server management platform providing SSH terminal, tunneling, and file editing. The POST '/credentials/:id/deploy-to-host' endpoint fails to verify if the records associated with the credentialId and targetHostId integer values belong to the requesting user. Additionally, differential errors in src/backend/database/routes/credentials.ts can reveal the existence of credential and host records and disclose their authType values. While encrypted passwords and keys remain protected, a victim host using key authentication may receive an outbound SSH connection attempt utilizing the attacker's public key.
Recommendations Update to version 2.5.1.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-79759
GHSA-CX8X-7RRR-R9X8
GHSA-W4CF-69FJ-G96F

Affected Products

Termix