Password Change Vulnerability in OpenC3 COSMOS Embedded Systems
CVE-2026-42084

8.1HIGH

Key Information:

Vendor

Openc3

Status
Vendor
CVE Published:
4 May 2026

What is CVE-2026-42084?

The OpenC3 COSMOS system allows users to change their passwords using a valid session token, bypassing the need for the old password. This flaw can be exploited by attackers who have gained access to a valid session token, leading to potential account hijacking, including administrative accounts. This vulnerability has been addressed in versions 6.10.5 and 7.0.0-rc3, which enforce stricter authentication requirements for password changes.

Affected Version(s)

cosmos < 6.10.5 < 6.10.5

cosmos >= 7.0.0.pre.rc1, < 7.0.0-rc3 < 7.0.0.pre.rc1, 7.0.0-rc3

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.