CVE-2026-12059: Cellopoint Celloos

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

The SSH service of CelloOS developed by Cellopoint has an Improper Access Control vulnerability, allowing authenticated remote attackers to bypass the enforced command restrictions and execute operating system commands outside the originally authorized scope.

Affected products

  • Cellopoint Celloos: before 4.8.0 Build 20260316 (fixed in 4.8.0 Build 20260316)

Published 2026-06-12. Last modified 2026-06-17.