CVE-2026-53548
Last modified
CVE-2026-53548 is a critical-severity vulnerability rated 9.6/10 on the CVSS scale. Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.6.1, the GET /host/db/host/:id/password endpoint in src/backend/database/routes/host.ts accepts an authenticated user's numeric host ID and the field=password or field=sudoPassword query without enforcing host ownership during credential resolution. EPSS estimates a 0.36% chance of exploitation in the next 30 days.
Description
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.6.1, the GET /host/db/host/:id/password endpoint in src/backend/database/routes/host.ts accepts an authenticated user's numeric host ID and the field=password or field=sudoPassword query without enforcing host ownership during credential resolution. A failed requester-scoped lookup can resolve the host with the owner's context and return the owner's plaintext credential, allowing any authenticated user with a valid JWT to enumerate sequential hosts.id values and retrieve SSH or sudo passwords belonging to other users. The disclosed credentials can then be used to access and control managed systems outside the Termix instance. This issue is fixed in version 2.6.1.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Termix-SSH | Termix | < 2.3.2 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-53548?
How severe is CVE-2026-53548?
How do I fix CVE-2026-53548?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-53540Python-Multipart is a streaming multipart parser for Python.…3.7
- CVE-2026-53541OliveTin gives access to predefined shell commands from a we…4.3
- CVE-2026-53542Termix is a web-based server management platform with SSH te…8.8
- CVE-2026-53545Termix is a web-based server management platform with SSH te…9.8
- CVE-2026-53546Termix is a web-based server management platform with SSH te…9.6
- CVE-2026-53547Termix is a web-based server management platform with SSH te…8.8
- CVE-2026-53549Termix is a web-based server management platform with SSH te…7.7
- CVE-2026-5355A vulnerability has been found in Trendnet TEW-657BRM 1.00.1…8.8
- CVE-2026-53550js-yaml is a JavaScript YAML parser and dumper. Prior to 4.2…5.3
- CVE-2026-53551free5GC is an open-source implementation of the 5G core netw…6.9
- CVE-2026-53552Goploy is an open-source automation deployment system. In ve…9.6
- CVE-2026-53553Goploy is an open-source automation deployment system. Prior…7.7
Are you affected by CVE-2026-53548?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
