CVE-2026-42454
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.1.0, all Docker container management endpoints in Termix interpolate...
Affects 0 products across 4 vendors.
Attacker injects OS commands through application inputs passed to system() or equivalent calls, leading to arbitrary command execution.
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
Termix, a web-based server management platform, is vulnerable to command injection due to improper handling of containerId parameters in Docker container management endpoints prior to version 2.1.0.
BSID: BS-2026-GLOBAL-224163-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2026-42454?
What is the CVSS score for CVE-2026-42454?
Is CVE-2026-42454 actively exploited?
How do I remediate CVE-2026-42454?
What systems are affected by CVE-2026-42454?
| CVE ID | CVE-2026-42454 |
|---|---|
| BSID | BS-2026-GLOBAL-224163-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| Published | 2026-05-08 |
| Last Modified | 2026-07-24 |
| ICS Relevance | 15% |
| Weakness (CWE) | |
| Domains | |
| Source | NVD |
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.1.0, all Docker container management endpoints in Termix interpolate the containerId URL path parameter and WebSocket message field directly into shell commands executed via ssh2.Client.exec() on remote managed servers without any sanitization or validation. An authenticated attacker can inject arbitrary OS commands by crafting a malicious container ID, achieving Remote Code Execution on any managed server. This issue has been patched in version 2.1.0.
Source: NIST NVD / MITRE CVE Database
An attacker with access to the Termix web interface can exploit this vulnerability by injecting malicious commands into the containerId URL path parameter or WebSocket message field. These commands are executed on remote managed servers via ssh2.Client.exec() without any sanitization or validation.
Exploitation Likelihood: CRITICAL
| Vendor | Product | Fixed Version |
|---|---|---|
| Client | — | — |
| Docker | — | — |
| Platform | — | — |
| Termix | — | — |
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | a0638f1bc72a8e5ba3403bbf218aece50f70b90d9a7ce63aeb4002a39dae57e89e091fb9706475a54bd316b3b8983ce8bb9049f4e4d09c0f891dba8aa255ff01 |
Critical Severity - Know Your Exposure
A CVSS 9.9 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →