CVE-2026-44632
Description
Yamcs is a mission control framework. Prior to 5.12.7, a server-side code injection vulnerability existed in the Yamcs algorithm evaluation engine org.yamcs.algorithms.JavaExprAlgorithmExecutionFactory, which dynamically compiled and evaluated user-controlled algorithm text through the Janino compiler without enforcing a secure sandbox, so an authenticated user with the ChangeMissionDatabase privilege could override an existing algorithm's text via the mission database REST API and inject Java code (for example using java.lang.Runtime) to achieve remote code execution on the underlying host operating system. This issue is fixed in versions 5.12.7 and 5.13.0, which disable algorithm editing by default.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.yamcs:yamcs-coreMaven | < 5.12.7 | 5.12.7 |
Affected products
2Patches
Vulnerability mechanics
References
6- github.com/yamcs/yamcs/commit/3c550348f866af4675d2ba4a51d8d12b7c7c6011nvdPatch
- github.com/yamcs/yamcs/commit/4ff8fda642ea8c3309a4d3f379aa77b763148992nvdPatch
- github.com/yamcs/yamcs/security/advisories/GHSA-524g-x36v-9wm6nvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-524g-x36v-9wm6ghsaADVISORY
- github.com/yamcs/yamcs/releases/tag/yamcs-5.12.7nvdRelease Notes
- github.com/yamcs/yamcs/releases/tag/yamcs-5.13.0nvdRelease Notes
News mentions
0No linked articles in our index yet.