PT-2026-50878 · Sima Gmbh · Bondix

·

CVE-2026-12104

·

Published

2026-06-19

·

Updated

2026-06-22

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/AU:Y/R:U/RE:L/U:Amber
Name of the Vulnerable Software and Affected Versions SIMA GmbH Bondix versions prior to 1.25.7.6
Description OS command injection exists in the environment and tunnel configuration functionality on Linux. An authenticated attacker with configuration write access can execute arbitrary operating-system commands by providing crafted configuration values to server-side scripts.
Recommendations Update to a version newer than 1.25.7.5.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12104

Affected Products

Bondix