Remote Code Execution in Termix Web-Based Server Management Platform
CVE-2026-79764
7.7HIGH
What is CVE-2026-79764?
Termix is a web-based server management platform that allows users to manage their servers with SSH terminal access, file editing, and more. A flaw exists in the /homepage/proxy endpoint between versions 2.5.0 and 2.5.1, where it inadequately validates the url query parameter from authenticated users. The lack of destination restrictions enables low-privilege accounts to execute requests to sensitive internal services, including RFC1918 and link-local addresses. This can lead to the unauthorized exfiltration of critical internal data and credentials. The vulnerability is addressed in version 2.5.1.
Affected Version(s)
Termix >= 2.5.0, < 2.5.1
