Arbitrary Code Execution Vulnerability in Yamcs Mission Control Framework
CVE-2026-55511

9.1CRITICAL

Key Information:

Vendor

Yamcs

Status
Vendor
CVE Published:
28 August 2026

What is CVE-2026-55511?

The Yamcs Mission Control Framework is susceptible to a significant vulnerability where users with SystemPrivilege.ControlArchiving can exploit the system by creating a double-quoted StreamSQL column name. This input, when processed, can lead to the generation of arbitrary Java code through various components in the system. As a result, an attacker can execute unauthorized Java code in the Yamcs server, jeopardizing mission data confidentiality and integrity. This vulnerability allows potential telemetry manipulation and denial of service attacks. The issue has been resolved in versions 5.12.8 and 5.13.2 of Yamcs.

Affected Version(s)

yamcs < 5.12.8 < 5.12.8

yamcs >= 5.13.0, < 5.13.2 < 5.13.0, 5.13.2

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.