Command Injection Vulnerability in Termix SSH Management Platform
CVE-2026-79761

6.6MEDIUM

Key Information:

Vendor

Termix-ssh

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-79761?

The Termix SSH management platform, versions 1.7.0 through 2.5.1, has a vulnerability in its SSH key deployment flow, where user-controlled public-key tokens can lead to command injection. The grep pattern is derived from a user-supplied token and is interpolated into shell commands, allowing an authenticated user to deploy crafted SSH credentials and execute arbitrary commands on the target host with elevated privileges. This issue has been resolved in version 2.5.1.

Affected Version(s)

Termix >= 1.7.0, < 2.5.1

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.