Webhook Misconfiguration in Termix Server Management Platform
CVE-2026-79760

6.4MEDIUM

Key Information:

Vendor

Termix-ssh

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-79760?

Termix, a web-based server management platform, is susceptible to a configuration flaw that allows authenticated users to exploit webhook or ntfy notification channels by specifying attacker-controlled destination URLs. This misconfiguration enables unauthorized server-side requests to internal HTTP services via the notification-channel test endpoint. The vulnerability results in potential exposure to internal services, as it bypasses destination allowlisting and private-address blocking, allowing attackers to manipulate HTTP methods and headers. This issue has been addressed in version 2.5.1, reinforcing the security posture of the platform.

Affected Version(s)

Termix >= 2.5.0, < 2.5.1

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.