CVE-2026-45749
8.1 HIGHTermix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities
Published: 2026-06-05 · Last updated: 2026-06-08
Severity and scoring
- CVSS
- 8.1 HIGH
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- CWE
- CWE-308
Affected products
| Vendor | Product |
|---|---|
| termix | termix |
Description
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The `POST /users/totp/disable` and `POST /users/totp/backup-codes` endpoints in Termix prior to version 2.3.2 accept the account password as a sole authentication factor for MFA-critical operations. An attacker who obtains a user's password (phishing, credential stuffing, the passwordHash leak in GHSA-xxxx) can disable TOTP entirely or regenerate backup codes, without ever possessing the TOTP device or knowing a valid TOTP code. This renders two-factor authentication ineffective. Version 2.3.2 patches the issue.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2026-45749
- [Other]https://github.com/Termix-SSH/Termix/releases/tag/release-2.3.2-tag
- [Vendor advisory]https://github.com/Termix-SSH/Termix/security/advisories/GHSA-wqfw-rqj7-fv9m
- [Vendor advisory]https://github.com/Termix-SSH/Termix/security/advisories/GHSA-wqfw-rqj7-fv9m
Related CVEs
Same vendor
- CVE-2026-45750 — Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities (9.0 CRITICAL)
- CVE-2026-45748 — Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities (9.8 CRITICAL)
- CVE-2026-45746 — Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities (9.0 CRITICAL)
- CVE-2026-45745 — Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities (8.0 HIGH)
- CVE-2026-45744 — Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities (9.9 CRITICAL)