Medium severity4.3GHSA Advisory· Published Jul 16, 2026· Updated Jul 18, 2026
CVE-2026-44595
CVE-2026-44595
Description
Yamcs is a mission control framework. Prior to 5.12.7, the IAM API endpoints listUsers, getUser, listGroups, and getGroup in yamcs-core did not enforce the required SystemPrivilege.ControlAccess check in yamcs-core/src/main/java/org/yamcs/http/api/IamApi.java, so any authenticated user, even one with low or no privileges, could enumerate all user accounts in the system including their usernames, superuser status, and group memberships. This issue is fixed in versions 5.12.7 and 5.13.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.yamcs:yamcs-coreMaven | < 5.12.7 | 5.12.7 |
Affected products
2Patches
Vulnerability mechanics
References
6- github.com/yamcs/yamcs/commit/0e12b518f103f24681299318a30a460fe4327b88nvdPatch
- github.com/yamcs/yamcs/commit/e90099fba98e96214217c195b6a5b87b5f46e51cnvdPatch
- github.com/yamcs/yamcs/security/advisories/GHSA-p2rj-mrmc-9w29nvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-p2rj-mrmc-9w29ghsaADVISORY
- github.com/yamcs/yamcs/releases/tag/yamcs-5.12.7nvdRelease Notes
- github.com/yamcs/yamcs/releases/tag/yamcs-5.13.0nvdRelease Notes
News mentions
0No linked articles in our index yet.