CVE-2026-12104
Authenticated OS Command Injection in Bondix
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
OS command injection in the environment and tunnel configuration functionality in SIMA GmbH Bondix through version 1.25.7.5 on Linux allows an authenticated attacker with configuration write access to execute arbitrary operating-system commands via crafted configuration values passed to server-side scripts.
| CWE | CWE-78 |
| Vendor | sima gmbh |
| Product | bondix server |
| Published | Jun 19, 2026 |
| Last Updated | Jun 19, 2026 |
Stay Ahead of the Next One
Get instant alerts for sima gmbh bondix server
Be the first to know when new unknown vulnerabilities affecting sima gmbh bondix server are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
SIMA GmbH / Bondix Server
0 โค 1.25.7.5
References
Credits
Jonas Friedli (avantguard cyber security AG)