PT-2026-97920 · Termix · Termix

CVE-2026-79762

·

Published

2026-09-24

·

Updated

2026-09-28

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Termix versions 1.7.0 through 2.5.0
Description Termix derives keys used to wrap Data Encryption Keys (DEK) for OIDC and WebAuthn users from committed default strings and the public userId salt within the src/backend/utils/user-crypto.ts file. Since OIDC SYSTEM SECRET and WEBAUTHN SYSTEM SECRET are not configured by default deployment artifacts, an attacker possessing an offline SQLite database copy can derive the wrapping key to recover the DEK and decrypt stored SSH passwords, private keys, and key passphrases. Password-authenticated users are not affected.
Recommendations Update to version 2.5.1.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-79762
GHSA-685G-CCVV-6P8M

Affected Products

Termix