PT-2026-97920 · Termix · Termix
CVE-2026-79762
·
Published
2026-09-24
·
Updated
2026-09-28
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Termix versions 1.7.0 through 2.5.0
Description
Termix derives keys used to wrap Data Encryption Keys (DEK) for OIDC and WebAuthn users from committed default strings and the public
userId salt within the src/backend/utils/user-crypto.ts file. Since OIDC SYSTEM SECRET and WEBAUTHN SYSTEM SECRET are not configured by default deployment artifacts, an attacker possessing an offline SQLite database copy can derive the wrapping key to recover the DEK and decrypt stored SSH passwords, private keys, and key passphrases. Password-authenticated users are not affected.Recommendations
Update to version 2.5.1.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Termix