Web-based Server Management Platform Vulnerability in Termix Desktop by Termix
CVE-2026-45745

8HIGH

Key Information:

Vendor

Termix-ssh

Status
Vendor
CVE Published:
5 June 2026

What is CVE-2026-45745?

Termix Desktop, a web-based server management platform, has a significant vulnerability starting from version 1.7.0 where TLS certificate validation is disabled. This flaw allows potential attackers to conduct man-in-the-middle attacks, intercepting and manipulating encrypted traffic between clients and Termix servers. As a result, users could unknowingly expose credentials and JSON Web Tokens (JWT) or session tokens during both login and normal operational use. Currently, no patches have been released to address this vulnerability.

Affected Version(s)

Termix >= 1.7.0, <= 2.2.1

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.