LDAP Injection Vulnerability in Yamcs Mission Control Framework
CVE-2026-42568
4.3MEDIUM
What is CVE-2026-42568?
Yamcs, a mission control framework, has been found to contain an LDAP injection vulnerability within the LdapAuthModule. This issue arises when the username parameter is directly inserted into the LDAP filter without the necessary escaping as mandated by RFC 4515. This flaw can lead to unauthorized access or manipulation of authentication processes. It is crucial for users to upgrade to Yamcs versions 5.13.0 or 5.12.7, which have resolved this vulnerability. For more details, you can refer to the releases and advisories available on GitHub.
Affected Version(s)
yamcs < 5.12.7
