๐Ÿ” CVE Alert

CVE-2026-55559

CRITICAL 9.8

Yamcs: Remote Code Execution via instance-template argument YAML injection (createInstance)

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs inserts templateArgs from POST /api/instances and PATCH /api/instances/{instance} into YAML through VarStatement.append in yamcs-core/src/main/java/org/yamcs/templating/VarStatement.java without YAML-context escaping. The rendered configuration is parsed by YamcsServer.createInstance and loaded by YamcsServerInstance, allowing an attacker to inject a services entry for org.yamcs.ProcessRunner. Deployments without security.yaml expose the operation through the guest superuser, while secured deployments require SystemPrivilege.CreateInstances. Successful exploitation executes commands as the Yamcs service account. This issue is fixed in versions 5.12.8 and 5.13.2.

CWE CWE-94 CWE-470 CWE-1336
Vendor yamcs
Product yamcs
Published Aug 28, 2026
Last Updated Aug 28, 2026
Stay Ahead of the Next One

Get instant alerts for yamcs yamcs

Be the first to know when new critical vulnerabilities affecting yamcs yamcs are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

yamcs / yamcs
< 5.12.8 >= 5.13.0, < 5.13.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/yamcs/yamcs/security/advisories/GHSA-73mf-m39p-wpm9 github.com: https://github.com/yamcs/yamcs/commit/549f295cf8c5496a5e799d6bec2432ef976c82aa github.com: https://github.com/yamcs/yamcs/commit/7192da1c49bdf5ab1d72e579a47766a7c43e87c8 github.com: https://github.com/yamcs/yamcs/releases/tag/yamcs-5.12.8 github.com: https://github.com/yamcs/yamcs/releases/tag/yamcs-5.13.2