Junglewise Threat Intelligence

CVE-2026-12059: Cellopoint CelloOS improper access control in SSH service

CVE-2026-12059 · Severity: high · CVSS 8.8 · Published 2026-06-12

Executive brief

Cellopoint CelloOS, an operating system used in security gateway appliances, contains a flaw in its remote management interface. An authorized user with limited access can bypass security restrictions to run unauthorized commands on the underlying system. This could allow an attacker to gain full control over the device, potentially leading to data theft or disruption of network security services.

Technical details

An improper access control vulnerability (CWE-1284) exists in the SSH service of Cellopoint CelloOS. The flaw resides in the mechanism intended to restrict users to a specific set of authorized commands. A remote attacker with valid low-privileged SSH credentials can exploit this to bypass the restricted shell or command environment. Successful exploitation allows the execution of arbitrary operating system commands with the privileges of the SSH service, potentially leading to full system compromise. The vendor released a patch on 2026-03-18, which was delivered via online update services.

Affected products

  • Cellopoint CelloOS before 4.8.0 Build 20260316

Timeline

  • 2026-03-18: patched: Vendor-side remediation released via online update service
  • 2026-06-12: disclosed: Public advisory issued by TWCERT/CC

References