Spaceapplications
Spaceapplications Yamcs: vulnerabilidades y CVE
Spaceapplications Yamcs tiene 21 vulnerabilidades publicadas, 16 de ellas en los últimos 12 meses. 8 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE21
Últimos 12 meses16
Críticas8
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-55566 | Media (4.3) | 0.38% | — | 28 ago 2026 | Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs processes attacker-controlled data from the /ext URL route in yamcs-web/src/main/webapp/projects/webapp/src/app/core/routes/extension.matcher.ts,… |
| CVE-2026-55565 | Crítica (9.9) | 0.65% | — | 28 ago 2026 | Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs LikeExpression.fillCode_getValueReturn in yamcs-core/src/main/java/org/yamcs/yarch/streamsql/LikeExpression.java inserts an unescaped LIKE pattern… |
| CVE-2026-55559 | Crítica (9.8) | 0.78% | — | 28 ago 2026 | Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs inserts templateArgs from POST /api/instances and PATCH /api/instances/{instance} into YAML through VarStatement.append in… |
| CVE-2026-55552 | Alta (7.5) | 0.55% | — | 28 ago 2026 | Yamcs is a mission control framework. Prior to 5.11.13, Yamcs StaticFileHandler.locateFile resolves an unauthenticated request path without using Path.normalize and Path.toAbsolutePath to confirm that the absolute path… |
| CVE-2026-55549 | Media (6.5) | 1.3% | — | 28 ago 2026 | Yamcs is a mission control framework. Prior to 5.9.4, Yamcs reflects an attacker-controlled redirect_uri parameter from GET /auth/authorize into yamcs-core/src/main/resources/auth/templates/authorize.html without… |
| CVE-2026-55547 | Media (4.3) | 0.34% | — | 28 ago 2026 | Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits SystemPrivilege.ControlAccess checks from IamApi.listRoles, IamApi.getRole, and IamApi.listPrivileges in… |
| CVE-2026-55545 | Media (6.5) | 0.45% | — | 28 ago 2026 | Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs WebSocket subscription handlers fail to enforce the privileges required by equivalent REST endpoints. PacketsApi.subscribePackets exposes the… |
| CVE-2026-55521 | Alta (8.8) | 0.52% | — | 28 ago 2026 | Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits authorization checks in IndexesApi.listPacketIndex, IndexesApi.listEventIndex, Cop1Api.disable, Cop1Api.resume, Cop1Api.initialize,… |
| CVE-2026-55511 | Crítica (9.1) | 0.68% | — | 28 ago 2026 | Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs allows a user with SystemPrivilege.ControlArchiving to create a double-quoted StreamSQL column name that is interpolated into generated Java source… |
| CVE-2026-55548 | Media (4.3) | 0.36% | — | 16 jul 2026 | Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, the PacketsApi.exportPackets endpoint in yamcs-core/src/main/java/org/yamcs/http/api/PacketsApi.java failed to enforce object-level ReadPacket privileges… |
| CVE-2026-46621 | Crítica (9.1) | 1.1% | — | 16 jul 2026 | Yamcs is a mission control framework. Prior to 5.12.7, the Yamcs script evaluation engine for Python algorithms dynamically compiled and evaluated user-controlled algorithm text using Jython through the JSR-223… |
| CVE-2026-46562 | Crítica (9.8) | 0.98% | — | 16 jul 2026 | Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScript algorithm text in… |
| CVE-2026-44632 | Crítica (9.1) | 1.1% | — | 16 jul 2026 | Yamcs is a mission control framework. Prior to 5.12.7, a server-side code injection vulnerability existed in the Yamcs algorithm evaluation engine org.yamcs.algorithms.JavaExprAlgorithmExecutionFactory, which… |
| CVE-2026-44596 | Crítica (9.8) | 2.1% | — | 16 jul 2026 | Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handled by yamcs-core/src/main/java/org/yamcs/http/auth/AuthHandler.java, lacked any rate limiting,… |
| CVE-2026-44595 | Media (4.3) | 1.1% | — | 16 jul 2026 | Yamcs is a mission control framework. Prior to 5.12.7, the IAM API endpoints listUsers, getUser, listGroups, and getGroup in yamcs-core did not enforce the required SystemPrivilege.ControlAccess check in… |
| CVE-2026-42568 | Media (4.3) | 1.0% | — | 10 jun 2026 | Yamcs is a mission control framework. Prior to versions 5.13.0 and 5.12.7, an LDAP injection vulnerability exists in `org.yamcs.security.LdapAuthModule` when constructing search filters. The username parameter is… |
| CVE-2023-45280 | Media (5.4) | 0.53% | — | 19 oct 2023 | Yamcs 5.8.6 allows XSS (issue 2 of 2). It comes with a Bucket as its primary storage mechanism. Buckets allow for the upload of any file. There's a way to upload an HTML file containing arbitrary JavaScript and then… |
| CVE-2023-45279 | Media (5.4) | 0.43% | — | 19 oct 2023 | Yamcs 5.8.6 allows XSS (issue 1 of 2). It comes with a Bucket as its primary storage mechanism. Buckets allow for the upload of any file. There's a way to upload a display referencing a malicious JavaScript file to the… |
| CVE-2023-45281 | Media (6.1) | 0.41% | — | 19 oct 2023 | An issue in Yamcs 5.8.6 allows attackers to obtain the session cookie via upload of crafted HTML file. |
| CVE-2023-45278 | Crítica (9.1) | 1.6% | — | 19 oct 2023 | Directory Traversal vulnerability in the storage functionality of the API in Yamcs 5.8.6 allows attackers to delete arbitrary files via crafted HTTP DELETE request. |
| CVE-2023-45277 | Alta (7.5) | 1.0% | — | 19 oct 2023 | Yamcs 5.8.6 is vulnerable to directory traversal (issue 1 of 2). The vulnerability is in the storage functionality of the API and allows one to escape the base directory of the buckets, freely navigate system… |