CVE-2026-53546: Termix: Missing authorization in SSH host credential resolution exposes stored credentials

Published Aug 19, 2026
·
Updated

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the terminal WebSocket accepts a user-controlled hostConfig.id and src/backend/ssh/host-resolver.ts resolves that host without requiring ownership or explicit access. When no credential is shared with the requester, resolveHostById performs an owner credential fallback, and src/backend/ssh/terminal.ts combines that credential with attacker-controlled ip, port, and username values. An authenticated low-privileged user can therefore make Termix authenticate to an attacker-controlled SSH server and disclose another user's stored SSH password or private-key material while the victim user's data key is unlocked. This issue is fixed in version 2.3.2.

Affected Software

1 affected component
Termix<2.3.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Termix to a version that resolves this vulnerability.

    Fixed in 2.3.2

Event History

Aug 19, 2026
CVE Published
via MITRE·08:36 PM
Data Sourced
via MITRE·08:36 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated low-privileged Termix user can exploit it. The attacker needs to be able to interact with the terminal WebSocket and supply a host configuration ID along with SSH connection values.

2

What conditions are required for credential disclosure?

The targeted host configuration must resolve to another user's credential through the owner credential fallback, and that victim user's data key must be unlocked. The attacker also needs an SSH server they control so Termix will attempt authentication using the exposed credential material.

3

Are deployments affected by default?

The issue is in the authorization behavior of SSH host credential resolution before version 2.3.2. The provided information does not identify a configuration setting or feature toggle that disables the affected behavior.

4

What should be done if an immediate upgrade is not possible?

The provided information does not document a workaround. Until version 2.3.2 can be deployed, limiting low-privileged user access to the terminal functionality and protecting access to stored SSH credentials can reduce exposure.

5

How can administrators determine whether they are affected?

Termix versions prior to 2.3.2 are affected. Review terminal WebSocket activity for low-privileged users supplying host configuration IDs they do not own or have explicit access to, especially where connection targets, ports, or usernames differ from the stored host configuration.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203