# CVE-2026-45749

## Summary

- **CVE ID:** CVE-2026-45749
- **Severity:** HIGH
- **CVSS Score:** 8.1 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N)
- **CWE:** CWE-308
- **Published:** Jun 5, 2026
- **Last Modified:** Jun 10, 2026

## Description

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The `POST /users/totp/disable` and `POST /users/totp/backup-codes` endpoints in Termix prior to version 2.3.2 accept the account password as a sole authentication factor for MFA-critical operations. An attacker who obtains a user's password (phishing, credential stuffing, the passwordHash leak in GHSA-xxxx) can disable TOTP entirely or regenerate backup codes, without ever possessing the TOTP device or knowing a valid TOTP code. This renders two-factor authentication ineffective. Version 2.3.2 patches the issue.

## Affected Products

- Termix-SSH — Termix (< 2.3.2)

## References

- [CNA](https://github.com/Termix-SSH/Termix/security/advisories/GHSA-wqfw-rqj7-fv9m)
- [CNA](https://github.com/Termix-SSH/Termix/releases/tag/release-2.3.2-tag)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.32%
- **EPSS Percentile:** 25.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._