Yamcs 是一个任务控制框架。在 5.12.8 和 5.13.2 版本之前,Yamcs 的 WebSocket 订阅处理程序未能强制执行等效 REST 端点所需权限。具体表现为: 在未验证 权限的情况下公开了数据包 WebSocket 主题; 在未验证 权限的情况下公开了算法状态 WebSocket 主题; 在未验证 权限的情况下公开了 MDB 变更 WebSocket 主题。因此,低权限的已认证用户可以接收超出其授权范围的遥测数据包、算法状态及任务数据库变更信息。该问题已在 5.12.8 和 5.13.2 版本
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55565 | 9.9 CRITICAL | Yamcs: Authenticated remote code execution via unescaped StreamSQL `LIKE` pattern compiled |
| CVE-2026-55559 | 9.8 CRITICAL | Yamcs: Remote Code Execution via instance-template argument YAML injection (createInstance |
| CVE-2026-55511 | 9.1 CRITICAL | Yamcs: Authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs ` |
| CVE-2026-55521 | 8.8 HIGH | Yamcs : Multiple Missing Function Level Access Control vulnerabilities in Yamcs Core API |
| CVE-2026-55552 | 7.5 HIGH | Yamcs: Unauthenticated Directory Traversal |
| CVE-2026-55549 | 6.5 MEDIUM | Yamcs: Reflected XSS in the URL of the Authorize Endpoint |
| CVE-2026-55547 | 4.3 MEDIUM | Yamcs: Missing Authorization on Role and Privilege Enumeration Endpoints Allows Any Authen |
| CVE-2026-55566 | 4.3 MEDIUM | Yamcs: DOM XSS in Extension Routing |
No comments yet