Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-79763— Termix: MFA-critical operations accept the account password as a sole factor (regression of CVE-2026-45749)

Quick assessment

Affected
Termix-SSH Termix
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Termix 是一个基于 Web 的服务器管理平台,具备 SSH 终端、隧道连接和文件编辑功能。在 2.4.0 至 2.5.1 版本中, 和 这两个 API 端点允许仅通过账户密码作为唯一的重新认证因素。这一漏洞源于 2.4.0 版本的一次重构,该重构回归(regressed)了为修复 CVE-2026-45749 而引入的双因素认证检查机制。 在源代码文件 中,函数 在 bcrypt 密码比对成功时即返回认证成功;而每个相关端点则允许将“密码”或“TOTP 验证码”作为可互换的认证凭据。这意味着,攻击者若已获取受

CVSS 5.3 · Medium EPSS 0.32% · P22
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-79763

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Termix: MFA-critical operations accept the account password as a sole factor (regression of CVE-2026-45749)
Source: CVE Program / CVE List V5
Vulnerability Description
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.4.0 until 2.5.1, the POST /users/totp/disable and POST /users/totp/backup-codes endpoints accept the account password as the sole reauthentication factor after a 2.4.0 refactor regressed the two-factor check introduced for CVE-2026-45749. In src/backend/database/routes/user-totp-routes.ts, verifyTotpReauth returns success when bcrypt.compare validates the password, while each endpoint chooses password or totp_code as an interchangeable credential. An attacker who has a victim's authenticated session and knows the password can disable TOTP or regenerate and invalidate backup codes without an authenticator or valid second factor, weakening the account to single-factor authentication. This issue is fixed in version 2.5.1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
使用单一因素认证机制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Termix-SSH Termix >= 2.4.0, < 2.5.1 -

II. Public POCs for CVE-2026-79763

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-79763

请登录查看更多情报信息。

Other References for CVE-2026-79763 (5)

Same Patch Batch · Termix-SSH · 2026-09-24 · 8 CVEs total

CVE-2026-79766 9.1 CRITICAL Termix: OS command injection in ACME/Let's Encrypt certificate-request handler via admin-c
CVE-2026-79764 7.7 HIGH Termix: Authenticated SSRF via `/homepage/proxy` — No Destination Allowlist
CVE-2026-79761 6.6 MEDIUM Termix: Command injection in SSH key deployment verification
CVE-2026-79760 6.4 MEDIUM Termix: Authenticated blind SSRF through notification channel test endpoints
CVE-2026-79762 5.5 MEDIUM Termix: Hardcoded default key encrypts all OIDC/WebAuthn users' stored SSH credentials — f
CVE-2026-79758 5.4 MEDIUM Termix: Authenticated users can read other users' host status and clear global SSH connect
CVE-2026-79759 4.3 MEDIUM Termix: Cross-User Information Disclosure via Missing Ownership Check in deploy-to-host En

IV. Related Vulnerabilities

V. Comments for CVE-2026-79763

No comments yet


Leave a comment