VYPR
High severityGHSA Advisory· Published Aug 28, 2026· Updated Aug 28, 2026

Yamcs has Unauthenticated Directory Traversal

CVE-2026-55552

Description

### Attack type: Unauthenticated remote

### Impact: Attackers can access any system files from the underlying host.

Affected components: HttpRequestHandler.java, StaticFileHandler.java

An Unauthenticated Directory Traversal vulnerability exists in Yamcs <=5.8.6, allowing anyone to access any file on the underlying operating system. This allows unauthenticated attackers to download sensitive files and data.

Steps to

Reproduce: 1. Start Yamcs and login as a user 2. Paste the following URL in the browser and press enter:

http://localhost:8090//etc/passwd
  1. The /etc/passwd file will be downloaded.

Acknowledgements

This vulnerability was discovered by Abderrahim Dahmani while solving a STARPWN 2025 CTF challenge at DEFCON 33 offered by VisionSpace Technologies.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.yamcs:yamcs-coreMaven
< 5.12.05.12.0

Affected products

1

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.