CVE-2026-42454
Termix, a web‑based server management platform, had a critical flaw that let attackers run arbitrary operating‑system commands on any managed server. The vulnerability existed in all versions before 2.1.0 and was fixed in that release. Users of older Termix installations were at risk of full server compromise.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Termix web‑based server management platform, versions earlier than 2.1.0, used by system administrators to manage servers via SSH.
Real-world impact
An attacker who can authenticate to Termix can craft a malicious container ID, causing the platform to execute arbitrary OS commands on the remote server. This can lead to complete control over the affected server, including data theft, modification, or destruction.
Why this severity
The CVSS score of 9.9 reflects that the flaw is network‑reachable, requires only low attack complexity and low privileges, needs no user interaction, and gives an attacker full confidentiality, integrity, and availability impact on the target server.
What to do about it
- 01Upgrade Termix to version 2.1.0 or later.
NVD-referenced vendor advisory
Timeline
- May 8, 2026 · May 8, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 11d agoAdvisory updatedThe NVD record was last revised.
- Jul 26, 2026 · 10d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.