Server Management Platform Vulnerability in Termix by Termix-SSH
CVE-2026-79759

4.3MEDIUM

Key Information:

Vendor

Termix-ssh

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-79759?

The Termix web-based server management platform, which provides features like SSH terminal access and file management, contains an improper access control vulnerability. In versions 1.7.0 through 2.5.0, the POST /credentials/:id/deploy-to-host endpoint fails to verify whether incoming credentialId and targetHostId values belong to the authenticated user. This oversight can be exploited by attackers to retrieve sensitive credential and host records, revealing information about their existence and associated authentication types. While encrypted passwords and keys remain secure, the exploit allows an attacker to initiate SSH connections using the victim's host credentials, posing significant risks to data security. Users are advised to upgrade to version 2.5.1, which addresses this vulnerability effectively.

Affected Version(s)

Termix >= 1.7.0, < 2.5.1

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.