Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-79762— Termix: Hardcoded default key encrypts all OIDC/WebAuthn users' stored SSH credentials — full offline decryption from a database copy

Quick assessment

Affected
Termix-SSH Termix
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Termix 是一个基于 Web 的服务器管理平台,具备 SSH 终端、隧道传输和文件编辑等功能。在版本 1.7.0 至 2.5.1 中,Termix 从提交的默认字符串以及 中公开的 userId 盐值派生出用于包装 OIDC 和 WebAuthn 用户的 Data Encryption Key(DEK)的密钥。由于 OIDC_SYSTEM_SECRET 和 WEBAUTHN_SYSTEM_SECRET 未在项目默认部署工件中配置,拥有离线 SQLite 数据库副本的攻击者可以推导出生成这些密钥所需的包装密钥,从

CVSS 5.5 · Medium EPSS 0.08% · P0
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-79762

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Termix: Hardcoded default key encrypts all OIDC/WebAuthn users' stored SSH credentials — full offline decryption from a database copy
Source: CVE Program / CVE List V5
Vulnerability Description
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.7.0 until 2.5.1, Termix derives the keys that wrap OIDC and WebAuthn users' Data Encryption Keys from committed default strings and the public userId salt in src/backend/utils/user-crypto.ts. Because OIDC_SYSTEM_SECRET and WEBAUTHN_SYSTEM_SECRET are not configured by the project's default deployment artifacts, an attacker with an offline SQLite database copy can derive the wrapping key, recover each affected user's DEK, and decrypt stored SSH passwords, private keys, and key passphrases. Password-authenticated users are not affected by this specific key derivation path. This issue is fixed in version 2.5.1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
使用硬编码的密码学密钥
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Termix-SSH Termix >= 1.7.0, < 2.5.1 -

II. Public POCs for CVE-2026-79762

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-79762

请登录查看更多情报信息。

Other References for CVE-2026-79762 (5)

Same Patch Batch · Termix-SSH · 2026-09-24 · 8 CVEs total

CVE-2026-79766 9.1 CRITICAL Termix: OS command injection in ACME/Let's Encrypt certificate-request handler via admin-c
CVE-2026-79764 7.7 HIGH Termix: Authenticated SSRF via `/homepage/proxy` — No Destination Allowlist
CVE-2026-79761 6.6 MEDIUM Termix: Command injection in SSH key deployment verification
CVE-2026-79760 6.4 MEDIUM Termix: Authenticated blind SSRF through notification channel test endpoints
CVE-2026-79758 5.4 MEDIUM Termix: Authenticated users can read other users' host status and clear global SSH connect
CVE-2026-79763 5.3 MEDIUM Termix: MFA-critical operations accept the account password as a sole factor (regression o
CVE-2026-79759 4.3 MEDIUM Termix: Cross-User Information Disclosure via Missing Ownership Check in deploy-to-host En

IV. Related Vulnerabilities

V. Comments for CVE-2026-79762

No comments yet


Leave a comment