CVE-2026-79758

MEDIUM CVSS 3.1: 5.4 EPSS 0.43%
Updated Sep 24, 2026
Termix-Ssh
Parameter Value
CVSS 5.4 (MEDIUM)
Fixed In 2.5.1
Type CWE-639 (Authorization Bypass), CWE-862 (Missing Authorization), CWE-284 (Improper Access Control)
Vendor Termix-Ssh
Public PoC No

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.8.0 until 2.5.1, authenticated Termix users can access the server-stats API without per-host authorization. GET /status returns statuses for hosts the requester cannot access, GET /status/:id accepts an attacker-supplied numeric host identifier, and POST /clear-connections permits a regular user to clear the global SSH connection pool. The affected src/backend/ssh/server-stats.ts routes expose host online or offline state and lastChecked timestamps and can disrupt other users' active sessions or pooled connections.

Unauthenticated requests remain blocked, but authentication alone does not preserve tenant isolation. This issue is fixed in version 2.5.1.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
None
No data modification
Availability
Low
Partial disruption

CVSS Vector v3.1

Vulnerable Products

termix-ssh:termix