Web-Based Server Management Platform Vulnerability in Termix
CVE-2026-79763

5.3MEDIUM

Key Information:

Vendor

Termix-ssh

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-79763?

The Termix web-based server management platform has a vulnerability in its two-factor authentication mechanism, allowing an attacker with access to a victim's authenticated session and knowledge of their password to disable TOTP (Time-based One-Time Password) or generate backup codes. This exploitation occurs due to a regression from a prior security update, leading to reliance on a single authentication factor for critical operations. Users are advised to upgrade to version 2.5.1 where this issue has been addressed.

Affected Version(s)

Termix >= 2.4.0, < 2.5.1

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.