CVE-2026-12104
HIGHSIMA Bondix Server - Authenticated OS Command Injection in Bondix
Title source: ruleDescription
OS command injection in the environment and tunnel configuration functionality in SIMA GmbH Bondix through version 1.25.7.5 on Linux allows an authenticated attacker with configuration write access to execute arbitrary operating-system commands via crafted configuration values passed to server-side scripts.
Scores
CVSS v4
8.6
EPSS
0.0132
EPSS Percentile
67.9%
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:L/U:Amber
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-78
Status
published
Products (2)
SIMA GmbH/Bondix Server
< 1.25.7.5
SIMA GmbH/Bondix Server
1.25.7.6
Published
Jun 19, 2026
Tracked Since
Jun 19, 2026