Yamcs 是一个任务控制框架。在 5.12.8 和 5.13.2 之前, 中的 方法会将未转义的 LIKE 模式插入到通过 和 编译的 Java 源代码中,而没有使用 进行转义处理。该 LIKE 模式可能来自以下接口: 、 、 、 或活动搜索,这些接口包括具有 、 或 权限的路径。如果 LIKE 模式中包含引号,即可注入 Java 代码,该代码将以 Yamcs 服务器进程的权限执行。此问题已在 5.12.8 和 5.13.2 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55559 | 9.8 CRITICAL | Yamcs: Remote Code Execution via instance-template argument YAML injection (createInstance |
| CVE-2026-55511 | 9.1 CRITICAL | Yamcs: Authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs ` |
| CVE-2026-55521 | 8.8 HIGH | Yamcs : Multiple Missing Function Level Access Control vulnerabilities in Yamcs Core API |
| CVE-2026-55552 | 7.5 HIGH | Yamcs: Unauthenticated Directory Traversal |
| CVE-2026-55545 | 6.5 MEDIUM | Yamcs: WebSocket subscription handlers omit the privilege checks their REST siblings enfor |
| CVE-2026-55549 | 6.5 MEDIUM | Yamcs: Reflected XSS in the URL of the Authorize Endpoint |
| CVE-2026-55547 | 4.3 MEDIUM | Yamcs: Missing Authorization on Role and Privilege Enumeration Endpoints Allows Any Authen |
| CVE-2026-55566 | 4.3 MEDIUM | Yamcs: DOM XSS in Extension Routing |
No comments yet