CVE-2026-79763: Termix: MFA-critical operations accept the account password as a sole factor (regression of CVE-2026-45749)

Published Sep 24, 2026
·
Updated

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.4.0 until 2.5.1, the POST /users/totp/disable and POST /users/totp/backup-codes endpoints accept the account password as the sole reauthentication factor after a 2.4.0 refactor regressed the two-factor check introduced for CVE-2026-45749. In src/backend/database/routes/user-totp-routes.ts, verifyTotpReauth returns success when bcrypt.compare validates the password, while each endpoint chooses password or totpcode as an interchangeable credential. An attacker who has a victim's authenticated session and knows the password can disable TOTP or regenerate and invalidate backup codes without an authenticator or valid second factor, weakening the account to single-factor authentication. This issue is fixed in version 2.5.1.

Affected Software

1 affected component
Termix Termix>=2.4.0<2.5.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Termix to a version that resolves this vulnerability.

    Fixed in 2.5.1

Event History

Sep 24, 2026
CVE Published
via MITRE·04:06 PM
Data Sourced
via MITRE·04:06 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What does an attacker need to exploit this issue?

The attacker needs both an authenticated session for the victim's account and knowledge of that account's password. They do not need the victim's authenticator or a valid TOTP code.

2

What actions can an attacker perform after exploiting it?

They can disable TOTP for the account or regenerate its backup codes, invalidating the existing codes. This weakens the account from two-factor to single-factor authentication.

3

Which versions should be remediated?

The issue affects Termix versions from 2.4.0 until the fix in version 2.5.1. Upgrade to version 2.5.1.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203