Description
The SSH service of CelloOS developed by Cellopoint has an Improper Access Control vulnerability, allowing authenticated remote attackers to bypass the enforced command restrictions and execute operating system commands outside the originally authorized scope.
Published: 2026-06-12
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The SSH service in Cellopoint's CelloOS includes an improper access control flaw that allows authenticated remote attackers to circumvent the command restrictions enforced by the system. This vulnerability, classified as CWE‑1284, means that a user who has successfully authenticated can execute arbitrary operating‑system commands beyond those originally authorized. The result is full remote code execution, giving an attacker complete control over the affected machine, compromising confidentiality, integrity, and availability.

Affected Systems

Cellopoint’s CelloOS platform is affected. The vulnerability applies to all installations of this OS that rely on the built‑in SSH service, regardless of version, as no specific version range is noted. Systems that are connected to the vendor’s update service should receive the remediation that was released on 2026‑03‑18. Offline, isolated, or otherwise disconnected systems must be manually updated to a fixed release from the vendor.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.7, indicating high severity. EPSS data is not available, but the absence of a KEV listing suggests limited evidence of active exploitation. The flaw requires authentication over SSH, so an attacker must first obtain valid user credentials or exploit a separate credential issue. Once authenticated, the attacker can bypass command restrictions and run any OS command, a direct path to compromise the host. The risk is high for environments where the SSH service is exposed externally or where privileged accounts have broad shell access.

Generated by OpenCVE AI on June 12, 2026 at 07:20 UTC.

Remediation

Vendor Solution

Systems connected to the vendor update service received vendor-side remediation on 2026-03-18. Systems that are offline, isolated, or otherwise unable to receive remote patches should be manually updated to any fixed release made available on or after 2026-03-18.


OpenCVE Recommended Actions

  • Apply the vendor‑issued patch released after 2026‑03‑18 to the CelloOS SSH service.
  • If the system cannot receive automated updates, manually download the fixed release from the vendor and install it.
  • Limit SSH access to trusted administrators and enforce least‑privilege user accounts to reduce the attack surface.

Generated by OpenCVE AI on June 12, 2026 at 07:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 12 Jun 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Cellopoint
Cellopoint cellos
Vendors & Products Cellopoint
Cellopoint cellos

Fri, 12 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 12 Jun 2026 06:45:00 +0000

Type Values Removed Values Added
Description The SSH service of CelloOS developed by Cellopoint has an Improper Access Control vulnerability, allowing authenticated remote attackers to bypass the enforced command restrictions and execute operating system commands outside the originally authorized scope.
Title Cellopoint|CelloOS - Improper Access Control
Weaknesses CWE-1284
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Cellopoint Cellos
cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2026-06-12T13:58:36.862Z

Reserved: 2026-06-12T06:01:41.825Z

Link: CVE-2026-12059

cve-icon Vulnrichment

Updated: 2026-06-12T13:57:37.072Z

cve-icon NVD

Status : Deferred

Published: 2026-06-12T07:16:19.780

Modified: 2026-06-12T16:00:18.860

Link: CVE-2026-12059

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-12T20:00:17Z

Weaknesses
  • CWE-1284

    Improper Validation of Specified Quantity in Input