PT-2026-3371 · Bastillion Io · Bastillion
Ana10Gy
·
Published
2026-01-17
·
Updated
2026-01-17
·
CVE-2026-1064
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:L/Au:M/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
bastillion-io Bastillion versions up to 4.0.1
Description
A command injection issue exists in the System Management Module of bastillion-io Bastillion. The issue is related to unknown processing within the file
src/main/java/io/bastillion/manage/control/SystemKtrl.java. Successful exploitation allows remote attackers to inject commands. The exploit has been made public.Recommendations
Update to a version later than 4.0.1. As a temporary workaround, consider restricting access to the
SystemKtrl.java file to minimize the risk of exploitation.Exploit
Fix
Special Elements Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bastillion