๐Ÿ” CVE Alert

CVE-2026-12104

UNKNOWN 0.0

Authenticated OS Command Injection in Bondix

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

OS command injection in the environment and tunnel configuration functionality in SIMA GmbH Bondix through version 1.25.7.5 on Linux allows an authenticated attacker with configuration write access to execute arbitrary operating-system commands via crafted configuration values passed to server-side scripts.

CWE CWE-78
Vendor sima gmbh
Product bondix server
Published Jun 19, 2026
Last Updated Jun 19, 2026
Stay Ahead of the Next One

Get instant alerts for sima gmbh bondix server

Be the first to know when new unknown vulnerabilities affecting sima gmbh bondix server are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

SIMA GmbH / Bondix Server
0 โ‰ค 1.25.7.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wiki.bondix.dev: https://wiki.bondix.dev/wiki/Security_Advisories#CVE-2026-12104_%E2%80%94_Authenticated_OS_Command_Injection_in_Bondix wiki.bondix.dev: https://wiki.bondix.dev/wiki/Downloads#Release_Notes

Credits

Jonas Friedli (avantguard cyber security AG)