๐Ÿ” CVE Alert

CVE-2026-55521

HIGH 8.8

Yamcs : Multiple Missing Function Level Access Control vulnerabilities in Yamcs Core API

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits authorization checks in IndexesApi.listPacketIndex, IndexesApi.listEventIndex, Cop1Api.disable, Cop1Api.resume, Cop1Api.initialize, Cop1Api.updateConfig, and TimeApi.setTime. An authenticated low-privilege user can read packet and event index metadata without ObjectPrivilegeType.ReadPacket, alter COP-1 link state without SystemPrivilege.ControlLinks, and manipulate simulation time. These operations can disclose telemetry metadata, disrupt telecommand handling, and affect system integrity and availability. This issue is fixed in versions 5.12.8 and 5.13.2.

CWE CWE-862
Vendor yamcs
Product yamcs
Published Aug 28, 2026
Last Updated Aug 28, 2026
Stay Ahead of the Next One

Get instant alerts for yamcs yamcs

Be the first to know when new high vulnerabilities affecting yamcs yamcs are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

yamcs / yamcs
< 5.12.8 >= 5.13.0, < 5.13.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/yamcs/yamcs/security/advisories/GHSA-962x-ccwf-8x6p github.com: https://github.com/yamcs/yamcs/commit/405139afa6094dfaf63ac17f32df1f808846c950 github.com: https://github.com/yamcs/yamcs/commit/493563679f838b86f3cdc5da9451d4a050ff6bd9 github.com: https://github.com/yamcs/yamcs/releases/tag/yamcs-5.12.8 github.com: https://github.com/yamcs/yamcs/releases/tag/yamcs-5.13.2