Beveiligingsadvies

CVE-2026-45743

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-06-05 17:56:53
Laatst bijgewerkt 2026-06-10 03:58:45
Toegewezen door GitHub_M
CVSS-score 8.1
Status PUBLISHED

Beschrijving

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. 16 file-manager endpoints in Termix prior to version 2.3.2 do not verify that the requesting user owns the SSH session identified by `sessionId`. An authenticated attacker who knows or guesses another user's active `sessionId` can read, write, delete, download, and execute files on the victim's connected SSH host. Version 2.3.2 patches the issue.