CVE-2026-42452
8.1Termix-SSH · Termix
Termix prior to version 2.1.0 allows low-privileged users to bypass the second-factor authentication requirement by misusing temporary login tokens on regular endpoints.
Executive summary
A missing authentication step in Termix prior to version 2.1.0 allows authenticated users to bypass two-factor authentication, posing a severe threat to account security and resource confidentiality.
Vulnerability
This is a missing critical step in authentication involving improper validation of temporary JSON Web Tokens issued during the login flow. The vulnerability requires low-privileged authentication to exploit.
Business impact
A successful exploit allows attackers to completely bypass mandatory second-factor authentication controls for targeted accounts, significantly reducing the security posture of critical server management infrastructure. With a CVSS score of 8.1, the vulnerability presents a high risk of unauthorized access, sensitive data exposure, and potential compromise of managed servers.
Remediation
Immediate Action: Update Termix to version 2.1.0 or later where the authentication middleware correctly validates temporary tokens.
Proactive Monitoring: Review authentication logs for anomalous login patterns where users with TOTP enabled bypass the second-factor verification step.
Compensating Controls: Enforce strict network-level access controls to limit exposure of the Termix web interface to trusted internal networks only.
Exploitation status
Public Exploit Available: No - there is no confirmed public exploit or weaponized module available in our tracked sources.
Analyst recommendation
Given the high severity score and potential for unauthorized administrative access, organizations utilizing the Termix platform must prioritize applying the version 2.1.0 security update immediately. Prompt patching is essential to restore robust multi-factor authentication guarantees and prevent account takeover scenarios.