CVE-2026-79763Medium· 5.3▾ SunlitTermix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.4.0 until 2.5.1, the POST /users/totp/disable and POST /users/totp/backup-codes endpoints accept the account password as…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.4.0 until 2.5.1, the POST /users/totp/disable and POST /users/totp/backup-codes endpoints accept the account password as the sole reauthentication factor after a 2.4.0 refactor regressed the two-factor check introduced for CVE-2026-45749. In src/backend/database/routes/user-totp-routes.ts, verifyTotpReauth returns success when bcrypt.compare validates the password, while each endpoint chooses password or totp_code as an interchangeable credential. An attacker who has a victim's authenticated session and knows the password can disable TOTP or regenerate and invalidate backup codes without an authenticator or valid second factor, weakening the account to single-factor authentication. This issue is fixed in version 2.5.1.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-79766Critical· 9.1Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities
CVE-2026-79762Medium· 5.5Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities
CVE-2026-79764High· 7.7Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities
CVE-2026-79760Medium· 6.4Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities
CVE-2026-79761Medium· 6.6Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities
CVE-2026-79759Medium· 4.3Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities