CVE-2026-45743

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. 16 file-manager endpoints in Termix prior to version 2.3.2 do not verify that the requesting user owns the SSH session identified by `sessionId`. An authenticated attacker who knows or guesses another user's active `sessionId` can read, write, delete, download, and execute files on the victim's connected SSH host. Version 2.3.2 patches the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:termix:termix:*:*:*:*:*:*:*:*

History

08 Jun 2026, 17:16

Type Values Removed Values Added
References () https://github.com/Termix-SSH/Termix/security/advisories/GHSA-5fqh-77cr-jj5x - Exploit, Mitigation, Vendor Advisory () https://github.com/Termix-SSH/Termix/security/advisories/GHSA-5fqh-77cr-jj5x - Exploit, Mitigation, Vendor Advisory

08 Jun 2026, 15:26

Type Values Removed Values Added
References () https://github.com/Termix-SSH/Termix/releases/tag/release-2.3.2-tag - () https://github.com/Termix-SSH/Termix/releases/tag/release-2.3.2-tag - Product, Release Notes
References () https://github.com/Termix-SSH/Termix/security/advisories/GHSA-5fqh-77cr-jj5x - () https://github.com/Termix-SSH/Termix/security/advisories/GHSA-5fqh-77cr-jj5x - Exploit, Mitigation, Vendor Advisory
CPE cpe:2.3:a:termix:termix:*:*:*:*:*:*:*:*
First Time Termix
Termix termix

05 Jun 2026, 18:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-05 18:17

Updated : 2026-06-08 17:16


NVD link : CVE-2026-45743

Mitre link : CVE-2026-45743

CVE.ORG link : CVE-2026-45743


JSON object : View

Products Affected

termix

  • termix
CWE
CWE-639

Authorization Bypass Through User-Controlled Key