Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-79758— Termix: Authenticated users can read other users' host status and clear global SSH connections

Quick assessment

Affected
Termix-SSH Termix
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Termix 是一个基于 Web 的服务器管理平台,具备 SSH 终端、隧道转发和文件编辑等功能。在版本 1.8.0 至 2.5.1 之间,已认证的 Termix 用户可以在未经主机级授权的情况下访问服务器状态(server-stats)API。具体表现为: 会返回请求者无权访问的主机状态信息; 接受攻击者提供的数字格式主机标识符; 允许普通用户清除全局 SSH 连接池。 受影响的端点 暴露了主机的在线/离线状态及最近检测时间戳,可能导致其他用户的活跃会话或连接池被中断。虽然未认证的请求仍被阻止,但仅靠用户认证无法

CVSS 5.4 · Medium EPSS 0.43% · P35
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-79758

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Termix: Authenticated users can read other users' host status and clear global SSH connections
Source: CVE Program / CVE List V5
Vulnerability Description
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.8.0 until 2.5.1, authenticated Termix users can access the server-stats API without per-host authorization. GET /status returns statuses for hosts the requester cannot access, GET /status/:id accepts an attacker-supplied numeric host identifier, and POST /clear-connections permits a regular user to clear the global SSH connection pool. The affected src/backend/ssh/server-stats.ts routes expose host online or offline state and lastChecked timestamps and can disrupt other users' active sessions or pooled connections. Unauthenticated requests remain blocked, but authentication alone does not preserve tenant isolation. This issue is fixed in version 2.5.1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
访问控制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Termix-SSH Termix >= 1.8.0, < 2.5.1 -

II. Public POCs for CVE-2026-79758

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-79758

请登录查看更多情报信息。

Other References for CVE-2026-79758 (3)

Same Patch Batch · Termix-SSH · 2026-09-24 · 8 CVEs total

CVE-2026-79766 9.1 CRITICAL Termix: OS command injection in ACME/Let's Encrypt certificate-request handler via admin-c
CVE-2026-79764 7.7 HIGH Termix: Authenticated SSRF via `/homepage/proxy` — No Destination Allowlist
CVE-2026-79761 6.6 MEDIUM Termix: Command injection in SSH key deployment verification
CVE-2026-79760 6.4 MEDIUM Termix: Authenticated blind SSRF through notification channel test endpoints
CVE-2026-79762 5.5 MEDIUM Termix: Hardcoded default key encrypts all OIDC/WebAuthn users' stored SSH credentials — f
CVE-2026-79763 5.3 MEDIUM Termix: MFA-critical operations accept the account password as a sole factor (regression o
CVE-2026-79759 4.3 MEDIUM Termix: Cross-User Information Disclosure via Missing Ownership Check in deploy-to-host En

IV. Related Vulnerabilities

V. Comments for CVE-2026-79758

No comments yet


Leave a comment