Webhook Misconfiguration in Termix Server Management Platform
CVE-2026-79760
6.4MEDIUM
What is CVE-2026-79760?
Termix, a web-based server management platform, is susceptible to a configuration flaw that allows authenticated users to exploit webhook or ntfy notification channels by specifying attacker-controlled destination URLs. This misconfiguration enables unauthorized server-side requests to internal HTTP services via the notification-channel test endpoint. The vulnerability results in potential exposure to internal services, as it bypasses destination allowlisting and private-address blocking, allowing attackers to manipulate HTTP methods and headers. This issue has been addressed in version 2.5.1, reinforcing the security posture of the platform.
Affected Version(s)
Termix >= 2.5.0, < 2.5.1
