CVE-2026-45745: CWE-295: Improper Certificate Validation in Termix-SSH Termix
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Starting in version 1.7.0, Termix Desktop (Electron) disables TLS certificate validation, allowing a machine-in-the-middle attacker to intercept and modify HTTPS traffic to the configured Termix server. This can lead to credential theft and JWT/session theft during login and normal use. As of time of publication, no known patched versions are available.
AI Analysis
Technical Summary
Termix is a web-based server management platform that includes SSH terminal, tunneling, and file editing features. Starting with version 1.7.0, the Termix Desktop client disables TLS certificate validation, which constitutes an improper certificate validation vulnerability (CWE-295). This flaw allows an attacker positioned between the client and server to intercept and alter HTTPS communications, potentially stealing user credentials and session tokens. The vulnerability has a CVSS 3.1 score of 8.0, indicating high severity. As of the publication date, no official fix or patch has been released.
Potential Impact
An attacker capable of performing a man-in-the-middle attack can intercept and modify HTTPS traffic between the Termix Desktop client and the Termix server. This can result in theft of user credentials and JWT/session tokens, compromising user authentication and session integrity. The vulnerability does not affect availability but impacts confidentiality and integrity.
Mitigation Recommendations
No official patch or fix is currently available for this vulnerability. Users should avoid using Termix Desktop versions 1.7.0 and later until a fix is released. Monitoring vendor advisories for updates is recommended. Since this is a client-side issue with disabled TLS certificate validation, no server-side mitigations are applicable.
CVE-2026-45745: CWE-295: Improper Certificate Validation in Termix-SSH Termix
Description
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Starting in version 1.7.0, Termix Desktop (Electron) disables TLS certificate validation, allowing a machine-in-the-middle attacker to intercept and modify HTTPS traffic to the configured Termix server. This can lead to credential theft and JWT/session theft during login and normal use. As of time of publication, no known patched versions are available.
CVSS v3.1
Score 8.0high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Termix is a web-based server management platform that includes SSH terminal, tunneling, and file editing features. Starting with version 1.7.0, the Termix Desktop client disables TLS certificate validation, which constitutes an improper certificate validation vulnerability (CWE-295). This flaw allows an attacker positioned between the client and server to intercept and alter HTTPS communications, potentially stealing user credentials and session tokens. The vulnerability has a CVSS 3.1 score of 8.0, indicating high severity. As of the publication date, no official fix or patch has been released.
Potential Impact
An attacker capable of performing a man-in-the-middle attack can intercept and modify HTTPS traffic between the Termix Desktop client and the Termix server. This can result in theft of user credentials and JWT/session tokens, compromising user authentication and session integrity. The vulnerability does not affect availability but impacts confidentiality and integrity.
Mitigation Recommendations
No official patch or fix is currently available for this vulnerability. Users should avoid using Termix Desktop versions 1.7.0 and later until a fix is released. Monitoring vendor advisories for updates is recommended. Since this is a client-side issue with disabled TLS certificate validation, no server-side mitigations are applicable.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-13T06:54:34.220Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a23130be29bf47b50a3ece4
Added to database: 06/05/2026, 18:18:51 UTC
Last enriched: 06/13/2026, 09:15:26 UTC
Last updated: 07/31/2026, 19:22:59 UTC
Views: 56
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.