Weak Key Derivation in Termix Server Management Platform
CVE-2026-79762

5.5MEDIUM

Key Information:

Vendor

Termix-ssh

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-79762?

The Termix server management platform has a vulnerability linked to its handling of user data encryption keys derived from default strings and public userId salts. Specifically, versions from 1.7.0 to 2.5.1 do not adequately secure OIDC and WebAuthn user data, leaving it susceptible to offline attacks. If an attacker has access to an offline SQLite database copy, they can recover the wrapping key, thus decrypting sensitive stored information such as SSH passwords, private keys, and key passphrases. This vulnerability does not affect users who authenticate via password. Termix has addressed this security issue in version 2.5.1.

Affected Version(s)

Termix >= 1.7.0, < 2.5.1

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.