Server Management Platform Vulnerability in Termix by Termix-SSH
CVE-2026-79759
What is CVE-2026-79759?
The Termix web-based server management platform, which provides features like SSH terminal access and file management, contains an improper access control vulnerability. In versions 1.7.0 through 2.5.0, the POST /credentials/:id/deploy-to-host endpoint fails to verify whether incoming credentialId and targetHostId values belong to the authenticated user. This oversight can be exploited by attackers to retrieve sensitive credential and host records, revealing information about their existence and associated authentication types. While encrypted passwords and keys remain secure, the exploit allows an attacker to initiate SSH connections using the victim's host credentials, posing significant risks to data security. Users are advised to upgrade to version 2.5.1, which addresses this vulnerability effectively.
Affected Version(s)
Termix >= 1.7.0, < 2.5.1
