Server Management Platform Vulnerability in Termix Affects User Authentication
CVE-2026-79758

5.4MEDIUM

Key Information:

Vendor

Termix-ssh

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-79758?

Termix, a web-based server management platform, is susceptible to an authentication bypass vulnerability that allows authenticated users to access restricted server-stats APIs without necessary per-host authorization. As a result, attackers can retrieve host status information and manipulate connection pools, adversely affecting other users' sessions. The vulnerability, which persists from version 1.8.0 through 2.5.0, fails to adequately enforce tenant isolation via authentication alone. This critical security issue can disrupt the normal operation and management of servers. It has been addressed in version 2.5.1, which reinforces authorization for accessing sensitive APIs.

Affected Version(s)

Termix >= 1.8.0, < 2.5.1

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.