Yamcs 是一个任务控制(Mission Control)框架。在 5.12.8 和 5.13.2 之前,Yamcs 会将来自 POST /api/instances 和 PATCH /api/instances/{instance} 的 通过 (位于 )插入到 YAML 中,且未进行 YAML 上下文转义。渲染后的配置由 解析,并由 加载,这使得攻击者能够注入一个针对 的服务条目。在未配置 的部署环境中,该操作可通过 guest 超级用户执行;而在已启用安全机制的部署环境中,则需要具备 权限。成功利用此漏洞后,
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55565 | 9.9 CRITICAL | Yamcs: Authenticated remote code execution via unescaped StreamSQL `LIKE` pattern compiled |
| CVE-2026-55511 | 9.1 CRITICAL | Yamcs: Authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs ` |
| CVE-2026-55521 | 8.8 HIGH | Yamcs : Multiple Missing Function Level Access Control vulnerabilities in Yamcs Core API |
| CVE-2026-55552 | 7.5 HIGH | Yamcs: Unauthenticated Directory Traversal |
| CVE-2026-55545 | 6.5 MEDIUM | Yamcs: WebSocket subscription handlers omit the privilege checks their REST siblings enfor |
| CVE-2026-55549 | 6.5 MEDIUM | Yamcs: Reflected XSS in the URL of the Authorize Endpoint |
| CVE-2026-55547 | 4.3 MEDIUM | Yamcs: Missing Authorization on Role and Privilege Enumeration Endpoints Allows Any Authen |
| CVE-2026-55566 | 4.3 MEDIUM | Yamcs: DOM XSS in Extension Routing |
No comments yet