CVE-2026-12104

OS command injection in the environment and tunnel configuration functionality in SIMA GmbH Bondix through version 1.25.7.5 on Linux allows an authenticated attacker with configuration write access to execute arbitrary operating-system commands via crafted configuration values passed to server-side scripts.
CVSS

No CVSS.

Configurations

No configuration.

History

19 Jun 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-19 14:16

Updated : 2026-06-22 20:16


NVD link : CVE-2026-12104

Mitre link : CVE-2026-12104

CVE.ORG link : CVE-2026-12104


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')