CVE-2026-79758Medium· 5.4▾ TwilightPoC availableTermix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.8.0 until 2.5.1, authenticated Termix users can access the server-stats API without per-host authorization. GET /status …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 29.7 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Exploit / PoC code exists
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.8.0 until 2.5.1, authenticated Termix users can access the server-stats API without per-host authorization. GET /status returns statuses for hosts the requester cannot access, GET /status/:id accepts an attacker-supplied numeric host identifier, and POST /clear-connections permits a regular user to clear the global SSH connection pool. The affected src/backend/ssh/server-stats.ts routes expose host online or offline state and lastChecked timestamps and can disrupt other users' active sessions or pooled connections. Unauthenticated requests remain blocked, but authentication alone does not preserve tenant isolation. This issue is fixed in version 2.5.1.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-79759Medium· 4.3Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities
CVE-2026-79764High· 7.7Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities
CVE-2026-79766Critical· 9.1Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities
CVE-2026-79762Medium· 5.5Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities
CVE-2026-79763Medium· 5.3Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities
CVE-2026-79760Medium· 6.4Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities