CVE-2026-1063 | bastillion-io Bastillion up to 4.0.1 Public Key Management System AuthKeysKtrl.java command injection (EUVD-2026-3127)
A vulnerability, which was classified as critical, was found in bastillion-io Bastillion up to 4.0.1. This vulnerability affects unknown code of the file src/main/java/io/bastillion/manage/control/AuthKeysKtrl.java of the component Public Key Management System. Such manipulation leads to command injection.
This vulnerability is referenced as CVE-2026-1063. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.