---
id: CVE-2026-75108
title: >-
  Next Terminal fails to enforce per-asset authorization checks on the portal
  ping and wake-on-LAN endpoints, allowing any authenticated user to probe and
  wake assets they are not granted access to
summary: >-
  Next Terminal fails to enforce per-asset authorization checks on the portal
  ping and wake-on-LAN endpoints, allowing any authenticated user to probe and
  wake assets they are not granted access to. Attackers can call these endpoints
  with …
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-862
vendor: next-terminal
product: next-terminal
affected:
  - next-terminal <= 3.3.7-b1
published: '2026-08-17'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T21:08:55.030'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-75108'
references:
  - url: 'https://github.com/next-terminal/next-terminal'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/next-terminal/next-terminal/issues/573'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/next-terminal-missing-per-asset-authorization-on-portal-endpoints
    label: disclosure@vulncheck.com
  - url: 'https://github.com/next-terminal/next-terminal/issues/573'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00294
epssPercentile: 0.19751
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-08-18T15:13:29.927123Z'
ingestedAt: '2026-09-17T18:25:15.984Z'
---

## Overview

Next Terminal fails to enforce per-asset authorization checks on the portal ping and wake-on-LAN endpoints, allowing any authenticated user to probe and wake assets they are not granted access to. Attackers can call these endpoints with arbitrary asset identifiers to retrieve asset information including display names, reachability status, connection timing, and network addresses, or trigger wake-on-LAN packets on unauthorized assets.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
