Metrics
Affected Vendors & Products
Tue, 20 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 19 Jan 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bastillion-io
Bastillion-io bastillion |
|
| Vendors & Products |
Bastillion-io
Bastillion-io bastillion |
Sat, 17 Jan 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been found in bastillion-io Bastillion up to 4.0.1. This vulnerability affects unknown code of the file src/main/java/io/bastillion/manage/control/AuthKeysKtrl.java of the component Public Key Management System. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | bastillion-io Bastillion Public Key Management System AuthKeysKtrl.java command injection | |
| Weaknesses | CWE-74 CWE-77 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2026-01-17T20:02:05.504Z
Updated: 2026-01-20T18:13:26.716Z
Reserved: 2026-01-16T19:14:38.317Z
Link: CVE-2026-1063
Updated: 2026-01-20T18:13:24.355Z
Status : Received
Published: 2026-01-17T20:15:53.947
Modified: 2026-01-17T20:15:53.947
Link: CVE-2026-1063
No data.