Skip to main content
EPSS 0.5%top 62%

CVE-2026-53548: CWE-285: Improper Authorization in Termix-SSH Termix

0
Critical
VulnerabilityCVE-2026-53548cvecve-2026-53548cwe-285cwe-639
Published: 08/19/2026 (08/19/2026, 20:35:35 UTC)
Source: CVE Database V5
Vendor/Project: Termix-SSH
Product: Termix

Description

CVE-2026-53548 is a critical improper authorization vulnerability in Termix-SSH's Termix platform prior to version 2.6.1. It allows any authenticated user with a valid JWT to enumerate host IDs and retrieve plaintext SSH or sudo passwords of other users by exploiting insufficient host ownership checks on a specific API endpoint. This can lead to unauthorized access and control of managed systems outside the Termix instance. The issue is fixed in version 2.6.1.

CVSS v3.1

Score 9.6critical

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

Affected software

Termix-SSH

Termix

Affected versions
<2.3.2
GitHub Actionsmore threats →ai
termix-ssh/Termix
pkg:github/termix-ssh/Termix
Affected versions
<2.6.1

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/11/2026, 05:02:19 UTC

Technical Analysis

Termix-SSH's Termix platform versions prior to 2.6.1 have an improper authorization vulnerability in the GET /host/db/host/:id/password endpoint. The endpoint accepts a numeric host ID and a query parameter requesting either the SSH password or sudo password but does not enforce that the requesting user owns the host. If a requester-scoped lookup fails, the system falls back to resolving the host with the owner's context, returning the owner's plaintext credentials. This allows an authenticated user with a valid JWT to enumerate sequential host IDs and retrieve sensitive credentials belonging to other users, potentially enabling unauthorized access to managed systems. The vulnerability is addressed in version 2.6.1.

Potential Impact

An attacker with any valid JWT token can enumerate host IDs and retrieve plaintext SSH or sudo passwords of other users, leading to unauthorized access and control over managed systems outside the Termix platform. This compromises confidentiality and integrity of credentials and systems managed by Termix. The CVSS score of 9.6 reflects the critical severity and the high impact on confidentiality and integrity without requiring user interaction.

Mitigation Recommendations

Upgrade Termix to version 2.6.1 or later, where this improper authorization vulnerability is fixed. No other mitigation is required as the vendor has provided an official fix.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-06-09T18:13:07.263Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6a861420acd9273b4997c7d9

Added to database: 08/19/2026, 20:37:52 UTC

Last enriched: 09/11/2026, 05:02:19 UTC

Last updated: 10/02/2026, 15:16:47 UTC

Views: 88

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses