Remote Code Execution in Termix Web-Based Server Management Platform
CVE-2026-79764

7.7HIGH

Key Information:

Vendor

Termix-ssh

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-79764?

Termix is a web-based server management platform that allows users to manage their servers with SSH terminal access, file editing, and more. A flaw exists in the /homepage/proxy endpoint between versions 2.5.0 and 2.5.1, where it inadequately validates the url query parameter from authenticated users. The lack of destination restrictions enables low-privilege accounts to execute requests to sensitive internal services, including RFC1918 and link-local addresses. This can lead to the unauthorized exfiltration of critical internal data and credentials. The vulnerability is addressed in version 2.5.1.

Affected Version(s)

Termix >= 2.5.0, < 2.5.1

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.