PatchSiren

SIMA GmbH CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH SIMA GmbH CVE published 2026-06-19

CVE-2026-12104

CVE-2026-12104 is an authenticated OS command injection vulnerability in SIMA GmbH Bondix through version 1.25.7.5 on Linux. The vulnerability allows an authenticated attacker with configuration write access to execute arbitrary operating-system commands via crafted configuration values passed to server-side scripts. This issue has a CVSS score of 8.6 and is classified as HIGH severity. The CVE was publis [truncated]