CVE-2026-53548: CWE-285: Improper Authorization in Termix-SSH Termix
CVE-2026-53548 is a critical improper authorization vulnerability in Termix-SSH's Termix platform prior to version 2.6.1. It allows any authenticated user with a valid JWT to enumerate host IDs and retrieve plaintext SSH or sudo passwords of other users by exploiting insufficient host ownership checks on a specific API endpoint. This can lead to unauthorized access and control of managed systems outside the Termix instance. The issue is fixed in version 2.6.1.
AI Analysis
Technical Summary
Termix-SSH's Termix platform versions prior to 2.6.1 have an improper authorization vulnerability in the GET /host/db/host/:id/password endpoint. The endpoint accepts a numeric host ID and a query parameter requesting either the SSH password or sudo password but does not enforce that the requesting user owns the host. If a requester-scoped lookup fails, the system falls back to resolving the host with the owner's context, returning the owner's plaintext credentials. This allows an authenticated user with a valid JWT to enumerate sequential host IDs and retrieve sensitive credentials belonging to other users, potentially enabling unauthorized access to managed systems. The vulnerability is addressed in version 2.6.1.
Potential Impact
An attacker with any valid JWT token can enumerate host IDs and retrieve plaintext SSH or sudo passwords of other users, leading to unauthorized access and control over managed systems outside the Termix platform. This compromises confidentiality and integrity of credentials and systems managed by Termix. The CVSS score of 9.6 reflects the critical severity and the high impact on confidentiality and integrity without requiring user interaction.
Mitigation Recommendations
Upgrade Termix to version 2.6.1 or later, where this improper authorization vulnerability is fixed. No other mitigation is required as the vendor has provided an official fix.
CVE-2026-53548: CWE-285: Improper Authorization in Termix-SSH Termix
Description
CVE-2026-53548 is a critical improper authorization vulnerability in Termix-SSH's Termix platform prior to version 2.6.1. It allows any authenticated user with a valid JWT to enumerate host IDs and retrieve plaintext SSH or sudo passwords of other users by exploiting insufficient host ownership checks on a specific API endpoint. This can lead to unauthorized access and control of managed systems outside the Termix instance. The issue is fixed in version 2.6.1.
CVSS v3.1
Score 9.6critical
Affected software
Termix-SSH
Termix
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Termix-SSH's Termix platform versions prior to 2.6.1 have an improper authorization vulnerability in the GET /host/db/host/:id/password endpoint. The endpoint accepts a numeric host ID and a query parameter requesting either the SSH password or sudo password but does not enforce that the requesting user owns the host. If a requester-scoped lookup fails, the system falls back to resolving the host with the owner's context, returning the owner's plaintext credentials. This allows an authenticated user with a valid JWT to enumerate sequential host IDs and retrieve sensitive credentials belonging to other users, potentially enabling unauthorized access to managed systems. The vulnerability is addressed in version 2.6.1.
Potential Impact
An attacker with any valid JWT token can enumerate host IDs and retrieve plaintext SSH or sudo passwords of other users, leading to unauthorized access and control over managed systems outside the Termix platform. This compromises confidentiality and integrity of credentials and systems managed by Termix. The CVSS score of 9.6 reflects the critical severity and the high impact on confidentiality and integrity without requiring user interaction.
Mitigation Recommendations
Upgrade Termix to version 2.6.1 or later, where this improper authorization vulnerability is fixed. No other mitigation is required as the vendor has provided an official fix.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-09T18:13:07.263Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a861420acd9273b4997c7d9
Added to database: 08/19/2026, 20:37:52 UTC
Last enriched: 09/11/2026, 05:02:19 UTC
Last updated: 10/02/2026, 15:16:47 UTC
Views: 88
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.