CVE-2026-53547: Termix: Account Takeover via Global Settings Disclosure

Published Aug 19, 2026
·
Updated

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the POST /database/export endpoint creates a user export that includes the global settings table even though the rest of the export is user-scoped. The settings table contains resetcode and tempresettoken password-reset artifacts, allowing a low-privileged authenticated user to recover another local account's reset code and complete the normal password-reset flow. Successful exploitation results in local-user account takeover and administrative compromise when the victim is an administrator. This issue is fixed in version 2.3.2.

Affected Software

1 affected component
Termix<2.3.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Termix to a version that resolves this vulnerability.

    Fixed in 2.3.2

Event History

Aug 19, 2026
CVE Published
via MITRE·08:34 PM
Data Sourced
via MITRE·08:34 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any low-privileged authenticated Termix user can exploit it. The impact is greatest where another local account, especially an administrator account, has password-reset artifacts stored in the global settings table.

2

What does an attacker need to take over another account?

The attacker needs valid low-privilege Termix credentials and access to the POST /database/export endpoint. They can recover another account's reset code or temporary reset token from the exported global settings data and use the normal password-reset flow.

3

Are affected systems exposed by default?

The issue is in the user export behavior of Termix versions prior to 2.3.2: although exports are otherwise user-scoped, the endpoint includes the global settings table. The provided information does not state whether access to this endpoint is restricted or disabled by default.

4

How can I determine whether my deployment is vulnerable?

Deployments running a Termix version earlier than 2.3.2 are affected. You can also verify exposure by reviewing whether exports generated through POST /database/export contain global settings entries with reset_code_ or temp_reset_token_ password-reset artifacts.

5

What should be done if patching cannot happen immediately?

The provided information identifies 2.3.2 as the fixed version but does not provide a supported workaround. Until upgrading, limit low-privilege user access to the affected export functionality where possible and treat password-reset artifacts exposed through prior exports as sensitive.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203