File Management Vulnerability in Termix Web-Based Server Management Platform
CVE-2026-45743

8.1HIGH

Key Information:

Vendor

Termix-ssh

Status
Vendor
CVE Published:
5 June 2026

What is CVE-2026-45743?

Termix, a web-based server management platform, has a vulnerability in its file management system that affects versions prior to 2.3.2. The platform does not correctly verify user ownership of its SSH sessions identified by 'sessionId'. This flaw enables an authenticated attacker who can guess or know another user's active sessionId to access, modify, delete, and execute files on the victim's SSH host. The issue has been addressed in version 2.3.2 of Termix.

Affected Version(s)

Termix < 2.3.2

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.