VYPR

Yamcs

by Yamcs

Source repositories

CVEs (9)

  • CVE-2026-46562CriJul 16, 2026
    risk 0.64cvss 9.8epss 0.01

    Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScript algorithm text in yamcs-core/src/main/java/org/yamcs/algorithms/ScriptAlgorithmExecutorFactory.java was constructed without a ClassFilter, so a user with the…

  • CVE-2026-46621CriJul 16, 2026
    risk 0.59cvss 9.1epss 0.01

    Yamcs is a mission control framework. Prior to 5.12.7, the Yamcs script evaluation engine for Python algorithms dynamically compiled and evaluated user-controlled algorithm text using Jython through the JSR-223 ScriptEngine API without enforcing a secure sandbox, so an…

  • CVE-2026-44632CriJul 16, 2026
    risk 0.59cvss 9.1epss 0.01

    Yamcs is a mission control framework. Prior to 5.12.7, a server-side code injection vulnerability existed in the Yamcs algorithm evaluation engine org.yamcs.algorithms.JavaExprAlgorithmExecutionFactory, which dynamically compiled and evaluated user-controlled algorithm text…

  • CVE-2026-44596MedJul 16, 2026
    risk 0.45cvss 6.5epss 0.02

    Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handled by yamcs-core/src/main/java/org/yamcs/http/auth/AuthHandler.java, lacked any rate limiting, account lockout, or failed-attempt throttling, so an…

  • CVE-2023-47311MedNov 20, 2023
    risk 0.40cvss 6.1epss 0.00

    An issue in Yamcs 5.8.6 allows attackers to send aribitrary telelcommands in a Command Stack via Clickjacking.

  • CVE-2023-45281MedOct 19, 2023
    risk 0.40cvss 6.1epss 0.00

    An issue in Yamcs 5.8.6 allows attackers to obtain the session cookie via upload of crafted HTML file.

  • CVE-2026-44595MedJul 16, 2026
    risk 0.31cvss 4.3epss 0.01

    Yamcs is a mission control framework. Prior to 5.12.7, the IAM API endpoints listUsers, getUser, listGroups, and getGroup in yamcs-core did not enforce the required SystemPrivilege.ControlAccess check in yamcs-core/src/main/java/org/yamcs/http/api/IamApi.java, so any…

  • CVE-2026-42568MedJun 10, 2026
    risk 0.31cvss 4.3epss 0.01

    Yamcs is a mission control framework. Prior to versions 5.13.0 and 5.12.7, an LDAP injection vulnerability exists in `org.yamcs.security.LdapAuthModule` when constructing search filters. The username parameter is inserted directly into the LDAP filter without proper RFC 4515…

  • CVE-2026-55548MedJul 16, 2026
    risk 0.00cvss 4.3epss 0.00

    Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, the PacketsApi.exportPackets endpoint in yamcs-core/src/main/java/org/yamcs/http/api/PacketsApi.java failed to enforce object-level ReadPacket privileges when a request omitted specific packet names: with an empty…