Metrics
Affected Vendors & Products
Tue, 20 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 19 Jan 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bastillion-io
Bastillion-io bastillion |
|
| Vendors & Products |
Bastillion-io
Bastillion-io bastillion |
Sat, 17 Jan 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in bastillion-io Bastillion up to 4.0.1. This issue affects some unknown processing of the file src/main/java/io/bastillion/manage/control/SystemKtrl.java of the component System Management Module. Performing a manipulation results in command injection. The attack can be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | bastillion-io Bastillion System Management SystemKtrl.java command injection | |
| Weaknesses | CWE-74 CWE-77 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2026-01-17T20:32:05.575Z
Updated: 2026-01-20T18:12:55.170Z
Reserved: 2026-01-16T19:14:43.492Z
Link: CVE-2026-1064
Updated: 2026-01-20T18:12:51.777Z
Status : Received
Published: 2026-01-17T21:15:49.693
Modified: 2026-01-17T21:15:49.693
Link: CVE-2026-1064
No data.