PT-2026-97918 · Termix · Termix
CVE-2026-79759
·
Published
2026-09-24
·
Updated
2026-09-29
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Termix versions 1.7.0 through 2.5.0
Description
Termix is a web-based server management platform providing SSH terminal, tunneling, and file editing. The POST '/credentials/:id/deploy-to-host' endpoint fails to verify if the records associated with the
credentialId and targetHostId integer values belong to the requesting user. Additionally, differential errors in src/backend/database/routes/credentials.ts can reveal the existence of credential and host records and disclose their authType values. While encrypted passwords and keys remain protected, a victim host using key authentication may receive an outbound SSH connection attempt utilizing the attacker's public key.Recommendations
Update to version 2.5.1.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Termix