Server Management Platform Vulnerability in Termix Affects User Authentication
CVE-2026-79758
5.4MEDIUM
What is CVE-2026-79758?
Termix, a web-based server management platform, is susceptible to an authentication bypass vulnerability that allows authenticated users to access restricted server-stats APIs without necessary per-host authorization. As a result, attackers can retrieve host status information and manipulate connection pools, adversely affecting other users' sessions. The vulnerability, which persists from version 1.8.0 through 2.5.0, fails to adequately enforce tenant isolation via authentication alone. This critical security issue can disrupt the normal operation and management of servers. It has been addressed in version 2.5.1, which reinforces authorization for accessing sensitive APIs.
Affected Version(s)
Termix >= 1.8.0, < 2.5.1
