OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-79764

HIGH · CVSS 7.7 EPSS 0.42% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The Termix web-based server management platform is vulnerable due to its /homepage/proxy endpoint, which allows authenticated users to make unrestricted HTTP requests, potentially exposing internal service data and cloud credentials. This flaw can be exploited by low-privilege or self-registered accounts, leading to significant data exfiltration risks. Organizations using versions 2.5.0 to 2.5.1 should prioritize upgrading to version 2.5.1 to mitigate this high-severity vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-79764
Severity
HIGH
CVSS
7.7
EPSS
0.42%

Original NVD Description

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.5.0 until 2.5.1, the /homepage/proxy endpoint accepts an authenticated user's url query parameter and passes it to http.get or https.get without destination restrictions. In src/backend/database/routes/homepage-proxy-routes.ts, new URL performs only syntactic validation, allowing requests to loopback, RFC1918, link-local, and cloud metadata destinations. The endpoint returns the complete fetched JSON response, so a low-privilege or self-registered account can exfiltrate internal service data and cloud credentials. This issue is fixed in version 2.5.1.