Junglewise Threat Intelligence

CVE-2026-45746: Termix broken access control in File Manager sessionId validation

CVE-2026-45746 · Severity: critical · CVSS 9 · Published 2026-06-05

Technologies: Termix-SSH Termix. Vendors: Termix-SSH.

Executive brief

Termix is a web-based platform used by administrators to manage remote servers through SSH and file editing tools. A security flaw allows a logged-in user to hijack the active file management sessions of other users by guessing or manipulating session identifiers. This could allow an attacker to read, modify, or delete sensitive files on a victim's remote server, and even execute malicious commands, leading to a full compromise of the managed infrastructure.

Technical details

A broken access control vulnerability (CWE-639) exists in the Termix File Manager due to improper validation of the 'sessionId' parameter. The backend fails to verify that the client-provided sessionId belongs to the currently authenticated user, trusting the user-controlled identifier instead. Because these session IDs are predictable numeric values, an authenticated attacker can iterate through IDs to hijack active SSH connections. This grants the attacker access to various file operations (read, write, upload) and the 'executeFile' endpoint, effectively resulting in Remote Code Execution (RCE) on the remote VPS instances managed by other users. The issue is addressed in version 2.3.2.

Affected products

  • Termix-SSH Termix < 2.3.2

Timeline

  • 2026-05-31: advisory: Initial GitHub security advisory published
  • 2026-06-05: disclosed: CVE published to NVD dataset

References

Related threats