Junglewise Threat Intelligence

CVE-2026-45749: Termix MFA bypass via single-factor authentication in TOTP endpoints

CVE-2026-45749 · Severity: high · CVSS 8.1 · Published 2026-06-05

Technologies: Termix-SSH Termix. Vendors: Termix-SSH.

Executive brief

Termix, a web-based server management platform, contains a security flaw that allows users to disable two-factor authentication (2FA) or reset recovery codes using only a password. This means that if an attacker steals a user's password through phishing or other means, they can bypass the extra layer of security intended to protect the account. Once 2FA is disabled, the attacker gains full access to the server management tools, potentially leading to unauthorized access to sensitive infrastructure and data.

Technical details

A vulnerability in the `POST /users/totp/disable` and `POST /users/totp/backup-codes` endpoints of Termix (prior to version 2.3.2) allows for the bypass of multi-factor authentication (MFA) requirements. The root cause is an improper authentication logic in `src/backend/database/routes/users.ts` that uses an 'OR' instead of an 'AND' condition when verifying credentials; providing a valid password allows the code to skip TOTP verification entirely. An attacker with a valid session and the user's password can disable MFA or generate new backup codes, effectively downgrading the account to single-factor authentication. This issue is resolved in version 2.3.2.

Affected products

  • Termix-SSH Termix <= 2.1.0

Timeline

  • 2026-05-31: advisory: GHSA-wqfw-rqj7-fv9m published
  • 2026-06-04: patched: Version 2.3.2 released
  • 2026-06-05: disclosed: CVE-2026-45749 published

References

Related threats