Skip to main content

Vendor/product archive

spaceapplications / yamcs CVEs

Beta · best-effort

11 CVEs tagged to spaceapplications / yamcs4 Critical, 1 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2026-55548

Published Jul 16, 2026

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, the PacketsApi.exportPackets endpoint in yamcs-core/src/main/java/org/yamcs/http/api/PacketsApi.java failed to en…

CVSS 4.3 · Medium
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2026-46621

Published Jul 16, 2026

Yamcs is a mission control framework. Prior to 5.12.7, the Yamcs script evaluation engine for Python algorithms dynamically compiled and evaluated user-controlled algorithm text u…

CVSS 9.1 · Critical
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2026-46562

Published Jul 16, 2026

Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScript algorithm text in yamcs-core/src/main/java/org/yamcs/algo…

CVSS 9.8 · Critical
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2026-44632

Published Jul 16, 2026

Yamcs is a mission control framework. Prior to 5.12.7, a server-side code injection vulnerability existed in the Yamcs algorithm evaluation engine org.yamcs.algorithms.JavaExprAlg…

CVSS 9.1 · Critical
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2026-44596

Published Jul 16, 2026

Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handled by yamcs-core/src/main/java/org/yamcs/http/auth/AuthHand…

CVSS 6.5 · Medium
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2026-44595

Published Jul 16, 2026

Yamcs is a mission control framework. Prior to 5.12.7, the IAM API endpoints listUsers, getUser, listGroups, and getGroup in yamcs-core did not enforce the required SystemPrivileg…

CVSS 4.3 · Medium
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2023-45280

Published Oct 19, 2023

Yamcs 5.8.6 allows XSS (issue 2 of 2). It comes with a Bucket as its primary storage mechanism. Buckets allow for the upload of any file. There's a way to upload an HTML file cont…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45279

Published Oct 19, 2023

Yamcs 5.8.6 allows XSS (issue 1 of 2). It comes with a Bucket as its primary storage mechanism. Buckets allow for the upload of any file. There's a way to upload a display referen…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45281

Published Oct 19, 2023

An issue in Yamcs 5.8.6 allows attackers to obtain the session cookie via upload of crafted HTML file.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45278

Published Oct 19, 2023

Directory Traversal vulnerability in the storage functionality of the API in Yamcs 5.8.6 allows attackers to delete arbitrary files via crafted HTTP DELETE request.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-45277

Published Oct 19, 2023

Yamcs 5.8.6 is vulnerable to directory traversal (issue 1 of 2). The vulnerability is in the storage functionality of the API and allows one to escape the base directory of the bu…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-11 of 11 CVEsPage 1 of 1