OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-79766

CRITICAL · CVSS 9.1 EPSS 0.39% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The Termix web-based server management platform is vulnerable to command injection due to improper handling of user-controlled domain and email values, allowing authenticated administrators to execute arbitrary operating-system commands. This critical vulnerability can lead to exposure of sensitive data, including databases and stored credentials, significantly compromising the security of affected systems. Organizations using Termix versions 2.4.1 to 2.5.0 should prioritize upgrading to version 2.5.1 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-79766
Severity
CRITICAL
CVSS
9.1
EPSS
0.39%

Original NVD Description

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.4.1 until 2.5.1, an authenticated Termix administrator can store attacker-controlled domain and email values through PATCH /users/acme-ssl-settings and trigger their interpolation into a certbot shell command through POST /users/acme-ssl-request. In src/backend/database/routes/acme-ssl-routes.ts, child_process.execSync invokes /bin/sh -c with those values only wrapped in double quotes, so shell metacharacters can execute arbitrary operating-system commands as the Termix backend process. Both HTTP webroot and DNS Cloudflare challenge modes are affected, and compromise exposes Termix databases, process secrets, stored credentials, and network reachability. This issue is fixed in version 2.5.1.