CVE-2026-79758
5.4 MEDIUMpublic exploit availablePublished 2026-09-24 · Updated 2026-09-24
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.8.0 until 2.5.1, authenticated Termix users can access the server-stats API without per-host authorization. GET /status returns statuses for hosts the requester cannot access, GET /status/:id accepts an attacker-supplied numeric host identifier, and POST /clear-connections permits a regular user to clear the global SSH connection pool. The affected src/backend/ssh/server-stats.ts routes expose host online or offline state and lastChecked timestamps and can disrupt other users' active sessions or pooled connections. Unauthenticated requests remain blocked, but authentication alone does not preserve tenant isolation. This issue is fixed in version 2.5.1.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
Weaknesses
CWE-284, CWE-639, CWE-862
Public exploit & PoC references
- https://github.com/Termix-SSH/Termix/commit/ddbdd5c437c2296607dfaa4265d6f63fbc1ca92e
- https://github.com/Termix-SSH/Termix/pull/1067
- https://github.com/Termix-SSH/Termix/releases/tag/release-2.5.1-tag
- https://github.com/Termix-SSH/Termix/security/advisories/GHSA-372w-6f3h-vcm4
- https://github.com/Termix-SSH/Termix/security/advisories/GHSA-372w-6f3h-vcm4
All references
- https://github.com/Termix-SSH/Termix/commit/ddbdd5c437c2296607dfaa4265d6f63fbc1ca92e
- https://github.com/Termix-SSH/Termix/pull/1067
- https://github.com/Termix-SSH/Termix/releases/tag/release-2.5.1-tag
- https://github.com/Termix-SSH/Termix/security/advisories/GHSA-372w-6f3h-vcm4
- https://github.com/Termix-SSH/Termix/security/advisories/GHSA-372w-6f3h-vcm4
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2026-52850PoC
- UNSCOREDCVE-2026-53626PoC
- UNSCOREDCVE-2026-56724PoC
- MEDIUMCVE-2026-61748PoC
- UNSCOREDCVE-2026-63204PoC
- UNSCOREDCVE-2026-63205PoC
- MEDIUMCVE-2026-69190PoC
- UNSCOREDCVE-2026-70476PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.