Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.3%top 77%

CVE-2026-42452: CWE-304: Missing Critical Step in Authentication in Termix-SSH Termix

0
High
VulnerabilityCVE-2026-42452cvecve-2026-42452cwe-304
Published: 05/08/2026 (05/08/2026, 22:54:12 UTC)
Source: CVE Database V5
Vendor/Project: Termix-SSH
Product: Termix

Description

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.1.0, /users/login issues a temporary JWT (temp_token) for TOTP-enabled accounts. That token carries a pendingTOTP state and should only be valid for the second-factor flow. However, the auth middleware accepts this token on regular authenticated endpoints. This effectively turns 2FA into single-factor (password) for impacted accounts. This issue has been patched in version 2.1.0.

CVSS v3.1

Score 8.1high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Affected software

GitHub Actionsmore threats →ai
termix-ssh/Termix
pkg:github/termix-ssh/Termix
Affected versions
<2.1.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 05/16/2026, 10:17:15 UTC

Technical Analysis

Termix-SSH's web-based server management platform issues a temporary JWT (temp_token) with a pendingTOTP state during login for TOTP-enabled accounts. This token should only be valid for completing the second-factor authentication step. However, in versions before 2.1.0, the authentication middleware erroneously accepts this token for normal authenticated requests, bypassing the second-factor requirement. This vulnerability (CWE-304) compromises the intended two-factor authentication mechanism, allowing attackers with valid passwords to authenticate without completing the second factor. The vulnerability has a CVSS 3.1 score of 8.1 (high severity) and was published on 2026-05-08. It has been patched in version 2.1.0.

Potential Impact

The vulnerability allows attackers who have obtained valid user passwords to bypass the second-factor authentication step, effectively reducing the security of accounts protected by TOTP-based 2FA to single-factor authentication. This increases the risk of unauthorized access to the Termix platform, potentially exposing server management capabilities and sensitive data. There are no known exploits in the wild at the time of publication.

Mitigation Recommendations

Upgrade Termix to version 2.1.0 or later, where this authentication bypass vulnerability has been patched. Since the issue is fixed in the official release, applying this update fully mitigates the risk. No additional mitigation steps are indicated by the vendor advisory.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-04-27T13:55:58.693Z
Cvss Version
3.1
State
PUBLISHED
Remediation Level
null

Threat ID: 69fe6c74cbff5d86103b91c1

Added to database: 05/08/2026, 23:06:28 UTC

Last enriched: 05/16/2026, 10:17:15 UTC

Last updated: 07/31/2026, 19:22:58 UTC

Views: 115

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses